<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog</title>
	<atom:link href="http://www.anti-malware-blog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Tue, 20 Jul 2010 08:25:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Antivir Solution Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 08:25:25 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AntivirSolutionPro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=958</guid>
		<description><![CDATA[The Emsisoft malware research team has   discoverd a new outbreak    of the Antivir Solution Pro adware. Emsisoft      Anti-Malware detects this malware as Adware.Win32.AntivirSolutionPro.
Antivir Solution Pro is a rogue security program, this  is  a new variant from AVSecuritySuite, Antivirus Suite, and Antivirus Soft. A [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has   discoverd a new outbreak    of the <strong>Antivir Solution Pro</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft      Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirSolutionPro" target="_blank">Adware.Win32.AntivirSolutionPro</a></strong>.</p>
<p><strong>Antivir Solution Pro</strong> is a rogue security program, this  is  a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecuritySuite" target="_blank"><strong>AVSecuritySuite</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSuite" target="_blank"><strong>Antivirus Suite</strong></a>, and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSoft" target="_blank"><strong>Antivirus Soft</strong></a>. A rogue    application  tries to trick you by displaying  false positive/misleading    scan results  report, which says that your  computer is infected with    viruses or  trojan, but you will not be able  to delete them before  you   purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%\%random%.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\AVSolution</li>
<li>HKEY_LOCAL_MACHINE\software\AVSuitE</li>
<li>HKEY_CURRENT_USER\software\AVSolution</li>
<li>HKEY_CURRENT_USER\software\AVSuitE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
ProxyServer = http=127.0.0.1:5643<br />
ProxyOverride = &lt;local&gt;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\PhishingFilter<br />
EnabledV8 = 0&#215;00000000 (0)<br />
Enabled = 0&#215;00000000 (0)</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_1.png"><img class="alignnone size-full wp-image-959" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_1.png" alt="" width="362" height="142" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_2.png"><img class="alignnone size-medium wp-image-960" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_3.png"><img class="alignnone size-medium wp-image-961" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_3-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_4.png"><img class="alignnone size-medium wp-image-962" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_4-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_5.png"><img class="alignnone size-medium wp-image-963" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_5-400x297.png" alt="" width="400" height="297" /></a></p>
<p><strong>How to remove the infection of Antivir Solution Pro </strong><strong>(Adware.Win32.</strong><strong>Antivir Solution Pro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong>. Run a full scan on all drives   and       move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/08/antimalware-doctor-adware-removal-instructions/" rel="bookmark" class="crp_title">Antimalware Doctor Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntivirusGT Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/07/07/antivirusgt-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/07/07/antivirusgt-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 17:22:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntivirusGT]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=952</guid>
		<description><![CDATA[The Emsisoft malware research team has        discoverd a new outbreak           of the AntivirusGT adware. Emsisoft                  Anti-Malware detects this malware as Adware.Win32.AntivirusGT.
AntivirusGT [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has        discoverd a new outbreak           of the <strong>AntivirusGT </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                  Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusGT" target="_blank"><strong>Adware.Win32.</strong><strong>AntivirusGT</strong></a>.</p>
<p><strong>AntivirusGT</strong> is a rogue security program clone of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirus7" target="_blank"><strong>Antivirus7</strong></a> or <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeAntivir" target="_blank">FakeAntivir</a></strong>, which is also a rogue   application that has become widespread.  A rogue   application        tries to trick you  by displaying  false     positive/misleading  scan       results  report, which  says that your      computer is infected  with       viruses or  trojan, but you  will not be     able  to delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\AVGT\AntivirusGT.exe</li>
<li>%AllUsersProfile%\Start Menu\AVGT\AntivirusGT.lnk</li>
<li>%AllUsersProfile%\Start Menu\AVGT\Uninstall.lnk</li>
<li>%UserProfile%\Desktop\AntivirusGT.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\EVA50C</li>
<li>HKEY_CURRENT_USER\software\WinV2</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;AVGT&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirusGT_1.png"><img class="alignnone size-medium wp-image-953" title="Adware.Win32.AntivirusGT" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirusGT_1-400x279.png" alt="" width="400" height="279" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirusGT_2.png"><img class="alignnone size-medium wp-image-954" title="Adware.Win32.AntivirusGT" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirusGT_2-400x322.png" alt="" width="400" height="322" /></a></p>
<p><strong>How to remove the infection of AntivirusGT</strong><strong> </strong><strong>(Adware.Win32.AntivirusGT</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                     Anti-Malware</a></strong>. Run a full scan on all drives  and       move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/13/antivirus7-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus7 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/a-fast-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">A-fast Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/07/07/antivirusgt-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defense Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 21:04:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DefenseCenter]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=946</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak           of the Defense Center adware.    Emsisoft                 [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has           discoverd a new outbreak           of the <strong>Defense Center </strong>adware.    <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                     Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefenseCenter" target="_blank">Adware.Win32.ProtectionCenter</a></strong>.</p>
<p><strong>Defense Center </strong>is a rogue security program. This    is   a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectionCenter" target="_blank"><strong>Protection Center</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank">Data Protection</a></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank"><strong>Digital Protection</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank"><strong>Your Protection</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>, and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue        application      tries to trick you  by displaying  false          positive/misleading  scan     results  report, which  says that your           computer is infected with      viruses or  trojan, but you  will   not    be     able  to delete them before you      purchase. This rogue  also found bundled with <a href="http://blog.emsisoft.com/2010/06/08/youve-got-twit-err-problems/" target="_blank"><strong>TDSS rootkit</strong></a>.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Defense Center\virus.mp3</li>
<li>%ProgramFiles%\Defense Center\about.ico</li>
<li>%ProgramFiles%\Defense Center\activate.ico</li>
<li>%ProgramFiles%\Defense Center\buy.ico</li>
<li>%ProgramFiles%\Defense Center\def.db</li>
<li>%ProgramFiles%\Defense Center\defcnt.exe</li>
<li>%ProgramFiles%\Defense Center\defext.dll</li>
<li>%ProgramFiles%\Defense Center\defhook.dll</li>
<li>%ProgramFiles%\Defense Center\help.ico</li>
<li>%ProgramFiles%\Defense Center\scan.ico</li>
<li>%ProgramFiles%\Defense Center\settings.ico</li>
<li>%ProgramFiles%\Defense Center\splash.mp3</li>
<li>%ProgramFiles%\Defense Center\Uninstall.exe</li>
<li>%ProgramFiles%\Defense Center\update.ico</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Defense Center.lnk</li>
<li>%UserProfile%\Desktop\Defense Center.lnk</li>
<li>%UserProfile%\Desktop\Defense Center Support.lnk</li>
<li>%UserProfile%\Local Settings\Temp\def.dat</li>
<li>%UserProfile%\Local Settings\Temp\defr.dat</li>
<li>%UserProfile%\Local Settings\Temp\dhdhtrdhdrtr5y</li>
<li>%UserProfile%\Local Settings\Temp\3c08.tmp</li>
<li>%UserProfile%\Local Settings\Temp\4a8f.tmp</li>
<li>%UserProfile%\Local Settings\Temp\4otjesjty.mof</li>
<li>%UserProfile%\Local Settings\Temp\23cd.tmp</li>
<li>%UserProfile%\Local Settings\Temp\3764.tmp</li>
<li>%UserProfile%\Local Settings\Temp\b8bc.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Defense Center.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Buy.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Defense Center\Defense Center Support.lnk</li>
</ul>
<p><strong>Create new/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\*\ShellEx\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_LOCAL_MACHINE\software\Defense Center</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Defense Center</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Defense Center&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_1.png"><img class="alignnone size-medium wp-image-947" title="Adware.Win32.DefenseCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_2.png"><img class="alignnone size-medium wp-image-948" title="Adware.Win32.DefenseCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_3.png"><img class="alignnone size-medium wp-image-949" title="Adware.Win32.DefenseCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_3-399x300.png" alt="" width="399" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_4.png"><img class="alignnone size-medium wp-image-950" title="Adware.Win32.DefenseCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.DefenseCenter_4-400x296.png" alt="" width="400" height="296" /></a></p>
<p><strong>How to remove the infection of Defense </strong><strong>Center </strong><strong>(Adware.Win32.</strong><strong>Defense</strong><strong>Center)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                    Anti-Malware</a></strong>. Run a full scan on all drives and       move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Security Suite Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 22:20:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AVSecuritySuite]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=942</guid>
		<description><![CDATA[The Emsi Software malware research team has  discoverd a new outbreak    of the AV Security Suite adware. Emsisoft     Anti-Malware detects this malware as Adware.Win32.AVSecuritySuite.
AV Security Suite is a rogue security program, this is  a new variant from Antivirus Suite, and Antivirus Soft. A rogue   [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has  discoverd a new outbreak    of the <strong>AV Security Suite</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecuritySuite" target="_blank">Adware.Win32.AVSecuritySuite</a></strong>.</p>
<p><strong>AV Security Suite</strong> is a rogue security program, this is  a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSuite" target="_blank"><strong>Antivirus Suite</strong></a>, and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSoft" target="_blank"><strong>Antivirus Soft</strong></a>. A rogue   application  tries to trick you by displaying  false positive/misleading   scan results  report, which says that your  computer is infected with   viruses or  trojan, but you will not be able  to delete them before you   purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%\%random%.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\avsoft</li>
<li>HKEY_LOCAL_MACHINE\software\avsuite</li>
<li>HKEY_CURRENT_USER\software\avsoft</li>
<li>HKEY_CURRENT_USER\software\avsuite</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run,  “%random%”</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run,  “%random%”</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.AVSecuritySuite_1.png"><img class="alignnone size-medium wp-image-943" title="Adware.Win32.AVSecuritySuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.AVSecuritySuite_1-400x303.png" alt="" width="400" height="303" /></a></p>
<p><strong>How to remove the infection of AV Security Suite </strong><strong>(Adware.Win32.</strong><strong>AVSecuritySuite</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared       Anti-Malware</a>. Run a full scan on all drives and move all detected       items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivir Solution Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/a-fast-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">A-fast Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protection Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 23:07:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ProtectionCenter]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=938</guid>
		<description><![CDATA[The Emsisoft malware research team has          discoverd a new outbreak           of the Protection Center adware.   Emsisoft                   [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has          discoverd a new outbreak           of the <strong>Protection Center </strong>adware.   <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                    Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectionCenter" target="_blank">Adware.Win32.ProtectionCenter</a></strong>.</p>
<p><strong>Protection Center </strong>is a rogue security program. This   is   a new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank">Data Protection</a></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank"><strong>Digital Protection</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank"><strong>Your Protection</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>, and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue       application      tries to trick you  by displaying  false         positive/misleading  scan     results  report, which  says that your          computer is infected with      viruses or  trojan, but you  will  not    be     able  to delete them before you      purchase. This rogue also found bundled with <a href="http://blog.emsisoft.com/2010/06/08/youve-got-twit-err-problems/" target="_blank"><strong>TDSS rootkit</strong></a>.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Protection Center\cntprot.exe</li>
<li>%ProgramFiles%\Protection Center\help.ico</li>
<li>%ProgramFiles%\Protection Center\scan.ico</li>
<li>%ProgramFiles%\Protection Center\settings.ico</li>
<li>%ProgramFiles%\Protection Center\splash.mp3</li>
<li>%ProgramFiles%\Protection Center\Uninstall.exe</li>
<li>%ProgramFiles%\Protection Center\update.ico</li>
<li>%ProgramFiles%\Protection Center\virus.mp3</li>
<li>%ProgramFiles%\Protection Center\about.ico</li>
<li>%ProgramFiles%\Protection Center\activate.ico</li>
<li>%ProgramFiles%\Protection Center\buy.ico</li>
<li>%ProgramFiles%\Protection Center\cnt.db</li>
<li>%ProgramFiles%\Protection Center\cntext.dll</li>
<li>%ProgramFiles%\Protection Center\cnthook.dll</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Protection Center Support.lnk</li>
<li>%UserProfile%\Local Settings\Temp\4otjesjty.mof</li>
<li>%UserProfile%\Local Settings\Temp\451d.tmp</li>
<li>%UserProfile%\Local Settings\Temp\3722.tmp</li>
<li>%UserProfile%\Local Settings\Temp\7461.tmp</li>
<li>%UserProfile%\Local Settings\Temp\cnt.dat</li>
<li>%UserProfile%\Local Settings\Temp\cntr.dat</li>
<li>%UserProfile%\Local Settings\Temp\dhdhtrdhdrtr5y</li>
<li>%UserProfile%\Local Settings\Temp\2bf7.tmp</li>
<li>%UserProfile%\Local Settings\Temp\4f4e.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Protection Center Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Buy.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Protection Center</li>
<li>HKEY_LOCAL_MACHINE\software\Protection Center</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Protection Center&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.ProtectionCenter_1.png"><img class="alignnone size-medium wp-image-939" title="Adware.Win32.ProtectionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.ProtectionCenter_1-400x296.png" alt="" width="400" height="296" /></a></p>
<p><strong>How to remove the infection of Protection</strong><strong> Center </strong><strong>(Adware.Win32.</strong><strong>Protection</strong><strong>Center)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                   Anti-Malware</a></strong>. Run a full scan on all drives and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SysAntivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 17:29:43 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SysAntivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=935</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak               of the SysAntivirus  adware. Emsisoft                [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak               of the<strong> SysAntivirus </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysAntivirus" target="_blank"><strong>Adware.Win32.SysAntivirus</strong></a>.</p>
<p><strong>SysAntivirus </strong>is a rogue security program, this is a  new variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XJRAntivirus" target="_blank"><strong>XJR Antivirus</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>AKM Antivirus 2010 Pro</strong></a> and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RTSAntivirus2010" target="_blank">RTS Antivirus 2010</a></strong>. The maker of this rogue give it name as <strong>Sysinternals Antivirus</strong>. A  rogue      application         tries to  trick you  by displaying   false         positive/misleading   scan        results  report, which   says that  your         computer is  infected   with       viruses or   trojan, but  you     will not be     able   to  delete  them  before you        purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\wp3.dat</li>
<li>%ProgramFiles%\wp4.dat</li>
<li>%ProgramFiles%\wpp.exe</li>
<li>%ProgramFiles%\adc_w32.dll</li>
<li>%ProgramFiles%\alggui.exe</li>
<li>%ProgramFiles%\nuar.old</li>
<li>%ProgramFiles%\skynet.dat</li>
<li>%ProgramFiles%\svchost.exe</li>
<li>%ProgramFiles%\Sysinternals Antivirus\Sysinternals Antivirus.exe</li>
<li>%UserProfile%\Desktop\Sysinternals Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk</li>
<li>C:\Sysinternals Antivirus\Sysinternals Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd</li>
<li>HKEY_CURRENT_USER\software\Sysinternals Antivirus</li>
<li>HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp</li>
<li>HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\Registration</li>
<li>HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\setdata</li>
<li>HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus</li>
<li>HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus</li>
<li>HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\Registration</li>
<li>HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\setdata</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SysAntivirus_1.png"><img class="alignnone size-medium wp-image-936" title="Adware.Win32.SysAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SysAntivirus_1-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of SysAntivirus </strong><strong>(Adware.Win32.SysAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Master AV Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 20:42:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SecurityMasterAV]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=929</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak              of the Security Master AV adware. Emsisoft              Anti-Malware detects this malware as Adware.Win32.SecurityMasterAV.
Security Master AV is a rogue security [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has discovered a new outbreak              of the <strong>Security Master AV</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft              Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMasterAV" target="_blank">Adware.Win32.SecurityMasterAV</a></strong>.</p>
<p><strong>Security Master AV </strong>is a rogue security software that   show false  warning  messages and show misleading scan results, this  is another variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MySecurityEngine" target="_blank"><strong>My Security Engine</strong></a>, or <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CleanUPAntivirus" target="_blank"><strong>CleanUP Antivirus</strong></a>. It will  start   automatically when your computer starts. The  installer will also   create  numerous harmless files on your computer,  usually at Recent   folder,  that are used to impersonate malware files.  Once the program   is running  it will scan your computer and then display  these files as   infections,  but will not allow you to remove them until  you purchase   the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%\SMAV.ico</li>
<li>%AllUsersProfile%\Application Data\%random%\SM%random%.exe</li>
<li>%AllUsersProfile%\Application Data\SM%random%AV\SM%random%AV.cfg</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Master AV.lnk</li>
<li>%UserProfile%\Application Data\Security Master AV\cookies.sqlite</li>
<li>%UserProfile%\Desktop\Security Master AV.lnk</li>
<li>%UserProfile%\Recent\dudl.exe</li>
<li>%UserProfile%\Recent\eb.tmp</li>
<li>%UserProfile%\Recent\fix.dll</li>
<li>%UserProfile%\Recent\hymt.exe</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\kernel32.exe</li>
<li>%UserProfile%\Recent\kernel32.tmp</li>
<li>%UserProfile%\Recent\PE.tmp</li>
<li>%UserProfile%\Recent\ppal.sys</li>
<li>%UserProfile%\Recent\SICKBOY.tmp</li>
<li>%UserProfile%\Recent\tempdoc.exe</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Recent\CLSV.sys</li>
<li>%UserProfile%\Start Menu\Security Master AV.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Master AV.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Security Master AV&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[1].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[2].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[3].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[4].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[5].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msfwsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OcHealthMon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WinSSUI.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>127.0.0.1       localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
<li>173.236.107.243 www.google.com</li>
<li>173.236.107.243 google.com</li>
<li>173.236.107.243 google.com.au</li>
<li>173.236.107.243 www.google.com.au</li>
<li>173.236.107.243 google.be</li>
<li>173.236.107.243 www.google.be</li>
<li>173.236.107.243 google.com.br</li>
<li>173.236.107.243 www.google.com.br</li>
<li>173.236.107.243 google.ca</li>
<li>173.236.107.243 www.google.ca</li>
<li>173.236.107.243 google.ch</li>
<li>173.236.107.243 www.google.ch</li>
<li>173.236.107.243 google.de</li>
<li>173.236.107.243 www.google.de</li>
<li>173.236.107.243 google.dk</li>
<li>173.236.107.243 www.google.dk</li>
<li>173.236.107.243 google.fr</li>
<li>173.236.107.243 www.google.fr</li>
<li>173.236.107.243 google.ie</li>
<li>173.236.107.243 www.google.ie</li>
<li>173.236.107.243 google.it</li>
<li>173.236.107.243 www.google.it</li>
<li>173.236.107.243 google.co.jp</li>
<li>173.236.107.243 www.google.co.jp</li>
<li>173.236.107.243 google.nl</li>
<li>173.236.107.243 www.google.nl</li>
<li>173.236.107.243 google.no</li>
<li>173.236.107.243 www.google.no</li>
<li>173.236.107.243 google.co.nz</li>
<li>173.236.107.243 www.google.co.nz</li>
<li>173.236.107.243 google.pl</li>
<li>173.236.107.243 www.google.pl</li>
<li>173.236.107.243 google.se</li>
<li>173.236.107.243 www.google.se</li>
<li>173.236.107.243 google.co.uk</li>
<li>173.236.107.243 www.google.co.uk</li>
<li>173.236.107.243 google.co.za</li>
<li>173.236.107.243 www.google.co.za</li>
<li>173.236.107.243 www.google-analytics.com</li>
<li>173.236.107.243 www.bing.com</li>
<li>173.236.107.243 search.yahoo.com</li>
<li>173.236.107.243 www.search.yahoo.com</li>
<li>173.236.107.243 uk.search.yahoo.com</li>
<li>173.236.107.243 ca.search.yahoo.com</li>
<li>173.236.107.243 de.search.yahoo.com</li>
<li>173.236.107.243 fr.search.yahoo.com</li>
<li>173.236.107.243 au.search.yahoo.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_1.png"><img class="alignnone size-medium wp-image-930" title="Adware.Win32.SecurityMasterAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_1-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_2.png"><img class="alignnone size-medium wp-image-931" title="Adware.Win32.SecurityMasterAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_3.png"><img class="alignnone size-medium wp-image-932" title="Adware.Win32.SecurityMasterAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_3-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_4.png"><img class="alignnone size-medium wp-image-933" title="Adware.Win32.SecurityMasterAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.SecurityMasterAV_4-400x222.png" alt="" width="400" height="222" /></a></p>
<p><strong>How to remove the infection of Security Master AV</strong><strong> </strong><strong>(Adware.Win32.SecurityMasterAV</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win Antispyware Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 28 May 2010 06:07:59 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[WinAntispywareCenter]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=923</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak               of the Win Antispyware Center  adware. Emsisoft              [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak               of the<strong> Win Antispyware Center </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinAntispywareCenter" target="_blank"><strong>Adware.Win32.</strong><strong>WinAntispywareCenter</strong></a>.</p>
<p><strong>Win Antispyware Center </strong>is a rogue security program. A  rogue      application         tries to  trick you  by displaying   false         positive/misleading   scan        results  report, which   says that  your         computer is  infected   with       viruses or   trojan, but  you     will not be     able   to  delete  them  before you        purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\WinAntispywareCenter\av.exe</li>
<li>%UserProfile%\Local Settings\Temp\10.tmp</li>
</ul>
<p><strong>Create or modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\DefaultIcon</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas\command</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start\command</li>
<li>HKEY_CURRENT_USER\software\Win Antispyware Center</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\.exe\shell\open\command<br />
(Default) = &#8220;C:\Program Files\WinAntispywareCenter\av.exe&#8221; /START &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command<br />
(Default) = &#8220;C:\Program Files\WinAntispywareCenter\av.exe&#8221; /START &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_1.png"><img class="alignnone size-medium wp-image-924" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_1-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_2.png"><img class="alignnone size-medium wp-image-925" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_3.png"><img class="alignnone size-medium wp-image-926" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_3-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of Win Antispyware Center </strong><strong>(Adware.Win32.</strong><strong>WinAntispywareCenter</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus Pro 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Your PC Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XJR Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/#comments</comments>
		<pubDate>Wed, 26 May 2010 06:56:56 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[XJRAntivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=919</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak              of the XJR Antivirus  adware. Emsisoft                [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak              of the<strong> XJR Antivirus </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XJRAntivirus" target="_blank"><strong>Adware.Win32.XJRAntivirus</strong></a>.</p>
<p><strong>XJR Antivirus </strong>is a rogue security program, this is a new variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>AKM Antivirus 2010 Pro</strong></a> and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RTSAntivirus2010" target="_blank">RTS Antivirus 2010</a></strong>. A  rogue     application         tries to  trick you  by displaying   false        positive/misleading   scan        results  report, which   says that your         computer is  infected   with       viruses or   trojan, but you     will not be     able   to  delete  them  before you       purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\wp4.dat</li>
<li>%ProgramFiles%\adc_w32.dll</li>
<li>%ProgramFiles%\alggui.exe</li>
<li>%ProgramFiles%\skynet.dat</li>
<li>%ProgramFiles%\svchost.exe</li>
<li>%ProgramFiles%\wp3.dat</li>
<li>%ProgramFiles%\XJR Antivirus\XJR Antivirus.exe</li>
<li>%UserProfile%\Desktop\XJR Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\XJR Antivirus\XJR Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp\Registration</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp\setdata</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\Registration</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\setdata</li>
</ul>
<p><strong>Modify registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\exefile\shell\open\command<br />
Old: = &#8220;%1&#8243; %*<br />
New:  = C:\Program Files\alggui.exe &#8220;%1&#8243; %*</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.XJRAntivirus_1.png"><img class="alignnone size-medium wp-image-920" title="Adware.Win32.XJRAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.XJRAntivirus_1-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of XJR Antivirus </strong><strong>(Adware.Win32.XJRAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong>. Run a full scan on all drives      and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ByteDefender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 20 May 2010 16:29:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ByteDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=908</guid>
		<description><![CDATA[The Emsisoft  malware research team has  discoverd a new outbreak          of the ByteDefender adware. Emsisoft           Anti-Malware detects this malware as Adware.Win32.ByteDefender.
ByteDefender is a rogue     security      [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong> malware research team has  discoverd a new outbreak          of the <strong>ByteDefender</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft           Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ByteDefender" target="_blank">Adware.Win32.ByteDefender</a></strong>.</p>
<p><strong>ByteDefender </strong>is a rogue     security      program.  This is a new variant from Winiguard/Winisoft    family.  The       author of ByteDefender also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemIron" target="_blank">SystemIron</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurePcAv" target="_blank">SecurePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafePcAv" target="_blank">SafePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">GuardWWW</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>,… etc. To further convince victim,  SystemIron will also create numerous junk files with random names on          your  computer that will be detected as malware when the program     scans      your  computer, but will not allow you to remove them until     you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\ByteDefender Software\ByteDefender\ByteDefender.exe</li>
<li>%ProgramFiles%\ByteDefender Software\ByteDefender\Uninstall.exe</li>
<li>%ProgramFiles%\ByteDefender Software\ByteDefender\always_delete.xml</li>
<li>%ProgramFiles%\ByteDefender Software\ByteDefender\always_skip.xml</li>
<li>%ProgramFiles%\ByteDefender Software\ByteDefender\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Start Menu\Programs\ByteDefender.lnk</li>
<li>%UserProfile%\Desktop\ByteDefender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\ByteDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ByteDefender</li>
<li>HKEY_CURRENT_USER\software\ByteDefender</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\agents</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\general</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\realtime</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\scanner</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\tasks</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\tasks\0</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\tasks\1</li>
<li>HKEY_CURRENT_USER\software\ByteDefender\updates</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;ByteDefender&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ByteDefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_7.png"><img class="alignnone size-medium wp-image-915" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_1.png"><img class="alignnone size-medium wp-image-909" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_2.png"><img class="alignnone size-medium wp-image-910" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_8.png"><img class="alignnone size-medium wp-image-916" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_8-400x239.png" alt="" width="400" height="239" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_3.png"><img class="alignnone size-medium wp-image-911" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_3-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_4.png"><img class="alignnone size-medium wp-image-912" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_4-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_6.png"><img class="alignnone size-full wp-image-914" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_6.png" alt="" width="363" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_5.png"><img class="alignnone size-full wp-image-913" title="Adware.Win32.ByteDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ByteDefender_5.png" alt="" width="368" height="137" /></a></p>
<p><strong>How to remove the infection of ByteDefender</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>ByteDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft            Anti-Malware</a>. Run a full scan on all drives and move all  detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemIron Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FakeCopyright Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 19 May 2010 09:51:57 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[FakeCopyright]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=904</guid>
		<description><![CDATA[The Emsisoft malware research team has          discoverd a new outbreak           of the FakeCopyright adware.   Emsisoft                    [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has          discoverd a new outbreak           of the<strong> FakeCopyright </strong>adware.   <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                    Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeCopyright" target="_blank">Adware.Win32.FakeCopyright</a></strong>.</p>
<p><strong>FakeCopyright </strong>trying to force users to pay a fee for illegal or copyrighted material that installed on the user computer. Once installed, this program will run automatically when starting Windows and shows a window like this:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeCopyright_1.png"><img class="alignnone size-medium wp-image-905" title="Adware.Win32.FakeCopyright" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeCopyright_1-400x349.png" alt="" width="400" height="349" /></a></p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\APManager\wallpaper.jpg</li>
<li>%UserProfile%\Application Data\APManager\apmanager.exe</li>
<li>%UserProfile%\Application Data\APManager\files</li>
<li>%UserProfile%\Application Data\APManager\iplog</li>
<li>%UserProfile%\Application Data\APManager\ispinfo</li>
<li>%UserProfile%\Application Data\APManager\settings.ini</li>
<li>%UserProfile%\Application Data\APManager\uninstall.exe</li>
<li>%UserProfile%\Application Data\APManager\languages\French.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\German.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Italian.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Portuguese.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Slovak.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Spanish.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\template.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Czech.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Danish.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\Dutch.lng</li>
<li>%UserProfile%\Application Data\APManager\languages\English.lng</li>
<li>%UserProfile%\Desktop\AP Manager.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\APManager</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;apmanager.exe&#8221;</li>
</ul>
<p><strong>How to remove the infection of FakeCopyright </strong><strong>(Adware.Win32.</strong><strong>FakeCopyright</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                   Anti-Malware</a></strong>. Run a full scan on all drives and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Components Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 15 May 2010 13:59:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DataProtection]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=897</guid>
		<description><![CDATA[The Emsisoft malware research team has         discoverd a new outbreak           of the Data Protection adware.  Emsisoft                   Anti-Malware detects [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has         discoverd a new outbreak           of the <strong>Data Protection </strong>adware.  <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                   Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank">Adware.Win32.DataProtection</a></strong>.</p>
<p><strong>Data Protection </strong>is a rogue security program. This  is   a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank"><strong>Digital Protection</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank"><strong>Your Protection</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>, and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue      application      tries to trick you  by displaying  false        positive/misleading  scan     results  report, which  says that your         computer is infected with      viruses or  trojan, but you  will not    be     able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Data Protection\virus.mp3</li>
<li>%ProgramFiles%\Data Protection\about.ico</li>
<li>%ProgramFiles%\Data Protection\activate.ico</li>
<li>%ProgramFiles%\Data Protection\buy.ico</li>
<li>%ProgramFiles%\Data Protection\dat.db</li>
<li>%ProgramFiles%\Data Protection\datext.dll</li>
<li>%ProgramFiles%\Data Protection\dathook.dll</li>
<li>%ProgramFiles%\Data Protection\datprot.exe</li>
<li>%ProgramFiles%\Data Protection\help.ico</li>
<li>%ProgramFiles%\Data Protection\scan.ico</li>
<li>%ProgramFiles%\Data Protection\settings.ico</li>
<li>%ProgramFiles%\Data Protection\splash.mp3</li>
<li>%ProgramFiles%\Data Protection\Uninstall.exe</li>
<li>%ProgramFiles%\Data Protection\update.ico</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Protection.lnk</li>
<li>%UserProfile%\Desktop\Data Protection.lnk</li>
<li>%UserProfile%\Desktop\Data Protection Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Buy.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Data Protection Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Data Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Protection\Settings.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\*\ShellEx\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_LOCAL_MACHINE\software\Data Protection</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Data Protection</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Data Protection&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_1.png"><img class="alignnone size-medium wp-image-898" title="Adware.Win32.DataProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_1-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_2.png"><img class="alignnone size-medium wp-image-899" title="Adware.Win32.DataProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_2-400x309.png" alt="" width="400" height="309" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_3.png"><img class="alignnone size-medium wp-image-900" title="Adware.Win32.DataProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_4.png"><img class="alignnone size-medium wp-image-901" title="Adware.Win32.DataProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.DataProtection_4-400x310.png" alt="" width="400" height="310" /></a></p>
<p><strong>How to remove the infection of Data Protection</strong><strong> </strong><strong>(Adware.Win32.Data</strong><strong>Protection</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                  Anti-Malware</a></strong>. Run a full scan on all drives and     move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FakeSecurityEssentials Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 14 May 2010 06:55:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[FakeSecurityEssentials]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=887</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak               of the FakeSecurityEssentials adware. Emsisoft                 [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak               of the <strong>FakeSecurityEssentials</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeSecurityEssentials" target="_blank"><strong>Adware.Win32.FakeSecurityEssentials</strong></a>.</p>
<p><strong>FakeSecurityEssentials </strong>is a rogue security program, that try to deceives the user with a GUI similar to Microsoft Security Essentials.  A  rogue security program tries to  trick you  by displaying   false         positive/misleading   scan        results  report, which   says that  your         computer is  infected   with       viruses or   trojan, but  you     will not be     able   to  delete  them  before you        purchase.</p>
<p><strong></strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_1.png"><img class="alignnone size-medium wp-image-888" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_1-399x278.png" alt="" width="399" height="278" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_2.png"><img class="alignnone size-medium wp-image-889" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_2-400x218.png" alt="" width="400" height="218" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_3.png"><img class="alignnone size-medium wp-image-890" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_3-399x278.png" alt="" width="399" height="278" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_4.png"><img class="alignnone size-medium wp-image-891" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_4-399x278.png" alt="" width="399" height="278" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_5.png"><img class="alignnone size-medium wp-image-892" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_5-400x195.png" alt="" width="400" height="195" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_6.png"><img class="alignnone size-medium wp-image-893" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_6-400x363.png" alt="" width="400" height="363" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_7.png"><img class="alignnone size-full wp-image-894" title="Adware.Win32.FakeSecurityEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.FakeSecurityEssentials_7.png" alt="" width="396" height="210" /></a></p>
<p><strong>How to remove the infection of FakeSecurityEssentials </strong><strong>(Adware.Win32.</strong><strong>FakeSecurityEssentials</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Essentials 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RTS Antivirus 2010 Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 11 May 2010 11:15:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=875</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak              of the RTS Antivirus 2010 adware. Emsisoft                [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak              of the <strong>RTS Antivirus 2010</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RTSAntivirus2010" target="_blank"><strong>Adware.Win32.RTSAntivirus2010</strong></a>.</p>
<p><strong>RTS Antivirus 2010 </strong>is a rogue security program, come from hxxp://www.rtsantivirus2010. com.  This is another variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>AKM Antivirus 2010 Pro</strong></a>. A  rogue     application         tries to  trick you  by displaying   false        positive/misleading   scan        results  report, which   says that your         computer is  infected   with       viruses or   trojan, but you     will not be     able   to  delete  them  before you       purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\RST Antivirus 2010\WININET.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\comdlg32.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\dwmapi.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\libclamav.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\oledlg.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\pthreadVC2.dll</li>
<li>%ProgramFiles%\RST Antivirus 2010\RST Antivirus 2010.exe</li>
<li>%ProgramFiles%\RST Antivirus 2010\uninstall.bat</li>
<li>%UserProfile%\Application Data\RST Antivirus 2010\WinDefPro.dat</li>
<li>%UserProfile%\Application Data\RST Antivirus 2010\db\daily.cvd</li>
<li>%UserProfile%\Desktop\RST Antivirus 2010.lnk</li>
<li>%UserProfile%\Start Menu\Programs\RST Antivirus 2010\Uninstall RST Antivirus 2010.lnk</li>
<li>%UserProfile%\Start Menu\Programs\RST Antivirus 2010\RST Antivirus 2010.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_1.png"><img class="alignnone size-medium wp-image-878" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_1-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_2.png"><img class="alignnone size-medium wp-image-879" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_2-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_3.png"><img class="alignnone size-medium wp-image-880" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_3-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_4.png"><img class="alignnone size-medium wp-image-881" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_4-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_5.png"><img class="alignnone size-medium wp-image-882" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_5-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_6.png"><img class="alignnone size-medium wp-image-883" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_6-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_7.png"><img class="alignnone size-medium wp-image-884" title="Adware.Win32.RSTAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.RSTAntivirus2010_7-400x300.png" alt="" width="400" height="300" /></a></p>
<p><strong>How to remove the infection of RTS Antivirus 2010 </strong><strong>(Adware.Win32.RTSAntivirus2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong>. Run a full scan on all drives      and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AKM Antivirus 2010 Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 07 May 2010 09:27:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AKMAntivirus2010Pro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=869</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak             of the AKM Antivirus 2010 Pro  adware. Emsisoft               [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak             of the<strong> AKM Antivirus 2010 Pro </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                       Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>Adware.Win32.AKMAntivirus2010Pro</strong></a>.</p>
<p><strong>AKM Antivirus 2010 Pro </strong>is a rogue security program.  A  rogue     application         tries to  trick you  by displaying  false        positive/misleading   scan        results  report, which  says that your         computer is  infected   with       viruses or  trojan, but you     will not be     able   to  delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\skynet.dat</li>
<li>%ProgramFiles%\svchost.exe</li>
<li>%ProgramFiles%\wp3.dat</li>
<li>%ProgramFiles%\wp4.dat</li>
<li>%ProgramFiles%\adc32.dll</li>
<li>%ProgramFiles%\alggui.exe</li>
<li>%ProgramFiles%\nuar.old</li>
<li>%ProgramFiles%\AKM Antivirus 2010 Pro\AKM Antivirus 2010 Pro.exe</li>
<li>%UserProfile%\Desktop\AKM Antivirus 2010 Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\AKM Antivirus 2010 Pro\AKM Antivirus 2010 Pro.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd</li>
<li>HKEY_CURRENT_USER\software\AKM Antivirus 2010 Pro</li>
<li>HKEY_CURRENT_USER\software\AKM Antivirus 2010 Pro\PC_protect</li>
<li>HKEY_CURRENT_USER\software\AKM Antivirus 2010 Pro\PC_protect\Registration</li>
<li>HKEY_CURRENT_USER\software\AKM Antivirus 2010 Pro\PC_protect\setdata</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_1.png"><img class="alignnone size-medium wp-image-870" title="Adware.Win32.AKMAntivirus2010Pro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_1-400x334.png" alt="" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_2.png"><img class="alignnone size-medium wp-image-871" title="Adware.Win32.AKMAntivirus2010Pro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_2-400x210.png" alt="" width="400" height="210" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_3.png"><img class="alignnone size-medium wp-image-872" title="Adware.Win32.AKMAntivirus2010Pro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AKMAntivirus2010Pro_3-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of AKM Antivirus 2010 Pro </strong><strong>(Adware.Win32.AKMAntivirus2010Pro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                       Anti-Malware</a></strong>. Run a full scan on all drives     and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Your PC Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCommander Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 07 May 2010 09:08:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PCommander]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=862</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak            of the PCommander adware. Emsisoft                    [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak            of the <strong>PCommander </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCommander" target="_blank"><strong>Adware.Win32.PCommander</strong></a>.</p>
<p><strong>PCommander </strong>is a rogue security program, this  is a  new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlComponents" target="_blank">Control Components</a> /</strong><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlCenter" target="_blank"><strong>Control Center</strong></a>.  A  rogue     application         tries to trick you  by displaying  false        positive/misleading   scan       results  report, which  says that your         computer is  infected  with       viruses or  trojan, but you     will not be     able   to delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\PCommander\settings.ini</li>
<li>%UserProfile%\Application Data\PCommander\uninstall.exe</li>
<li>%UserProfile%\Application Data\PCommander\ccagent.exe</li>
<li>%UserProfile%\Application Data\PCommander\ccmain.exe</li>
<li>%UserProfile%\Application Data\PCommander\faq\guide.html</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\06.png</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\07.png</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\08.png</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\09.png</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\10.png</li>
<li>%UserProfile%\Application Data\PCommander\faq\images\05.png</li>
<li>%UserProfile%\Desktop\PCommander.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCommander</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run    “ccagent.exe”</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_4.png"><img class="alignnone size-medium wp-image-866" title="Adware.Win32.PCommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_4-400x276.png" alt="" width="400" height="276" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_3.png"><img class="alignnone size-medium wp-image-865" title="Adware.Win32.PCommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_3-400x268.png" alt="" width="400" height="268" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_2.png"><img class="alignnone size-medium wp-image-864" title="Adware.Win32.PCommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_2-400x304.png" alt="" width="400" height="304" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_1.png"><img class="alignnone size-medium wp-image-863" title="Adware.Win32.PCommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.PCommander_1-351x400.png" alt="" width="351" height="400" /></a></p>
<p><strong>How to remove the infection of PCommander </strong><strong>(Adware.Win32.PCommander</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong>. Run a full scan on all drives    and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Components Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeCopyright Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A-fast Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/06/a-fast-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/06/a-fast-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 06 May 2010 05:23:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AFastAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=855</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak            of the A-fast Antivirus adware. Emsisoft                   [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak            of the <strong>A-fast Antivirus</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AFastAntivirus" target="_blank"><strong>Adware.Win32.AFastAntivirus</strong></a>.</p>
<p><strong>A-fast Antivirus </strong>is a rogue security program come from hxxp://www.a-fast .com.  A  rogue     application         tries to trick you  by displaying  false        positive/misleading   scan       results  report, which  says that your         computer is  infected  with       viruses or  trojan, but you     will not be     able   to delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\A-fast\A-fast.exe</li>
<li>%UserProfile%\Desktop\A-fast Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\A-fast</li>
<li>HKEY_CURRENT_USER\software\A-fast\Activation</li>
<li>HKEY_CURRENT_USER\software\A-fast\Security</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;fast&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_2.png"><img class="alignnone size-medium wp-image-858" title="Adware.Win32.AFastAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_2-400x310.png" alt="" width="400" height="310" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_3.png"><img class="alignnone size-medium wp-image-859" title="Adware.Win32.AFastAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_3-400x379.png" alt="" width="400" height="379" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_4.png"><img class="alignnone size-medium wp-image-860" title="Adware.Win32.AFastAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.AFastAntivirus_4-400x314.png" alt="" width="400" height="314" /></a></p>
<p><strong>How to remove the infection of A-fast Antivirus </strong><strong>(Adware.Win32.AFastAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong>. Run a full scan on all drives    and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/06/a-fast-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ACommander Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 06 May 2010 04:44:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ACommander]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=847</guid>
		<description><![CDATA[The Emsisoft malware research team has           discoverd a new outbreak           of the ACommander adware. Emsisoft                     [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak           of the <strong>ACommander </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ACommander" target="_blank"><strong>Adware.Win32.ACommander</strong></a>.</p>
<p><strong>ACommander </strong>is a rogue security program, this  is a new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlComponents" target="_blank">Control Components</a> /</strong><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlCenter" target="_blank"><strong>Control Center</strong></a>.  A  rogue    application         tries to trick you  by displaying  false       positive/misleading   scan       results  report, which  says that your        computer is  infected  with       viruses or  trojan, but you    will not be     able   to delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\ACommander\settings.ini</li>
<li>%UserProfile%\Application Data\ACommander\uninstall.exe</li>
<li>%UserProfile%\Application Data\ACommander\ccagent.exe</li>
<li>%UserProfile%\Application Data\ACommander\ccmain.exe</li>
<li>%UserProfile%\Application Data\ACommander\faq\guide.html</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\06.png</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\07.png</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\08.png</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\09.png</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\10.png</li>
<li>%UserProfile%\Application Data\ACommander\faq\images\05.png</li>
<li>%UserProfile%\Desktop\ACommander.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ACommander</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run   “ccagent.exe”</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_1.png"><img class="alignnone size-medium wp-image-848" title="Adware.Win32.ACommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_1-400x276.png" alt="" width="400" height="276" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_2.png"><img class="alignnone size-medium wp-image-849" title="Adware.Win32.ACommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_2-351x400.png" alt="" width="351" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_3.png"><img class="alignnone size-medium wp-image-850" title="Adware.Win32.ACommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_3-400x304.png" alt="" width="400" height="304" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_4.png"><img class="alignnone size-medium wp-image-851" title="Adware.Win32.ACommander" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.ACommander_4-400x268.png" alt="" width="400" height="268" /></a></p>
<p><strong>How to remove the infection of ACommander </strong><strong>(Adware.Win32.ACommander</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                     Anti-Malware</a></strong>. Run a full scan on all drives   and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Components Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeCopyright Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Security Engine Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 09:14:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[MySecurityEngine]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=841</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak             of the My Security Engine adware. Emsisoft             Anti-Malware detects this malware as Adware.Win32.MySecurityEngine.
My Security Engine is a rogue security software that [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsisoft malware research team has discovered a new outbreak             of the <strong>My Security Engine</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft             Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MySecurityEngine" target="_blank">Adware.Win32.MySecurityEngine</a></strong>.</p>
<p><strong>My Security Engine </strong>is a rogue security software that  show false  warning  messages and show misleading scan results, this is another variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CleanUPAntivirus" target="_blank"><strong>CleanUP Antivirus</strong></a>. It will  start  automatically when your computer starts. The  installer will also  create  numerous harmless files on your computer,  usually at Recent  folder,  that are used to impersonate malware files.  Once the program  is running  it will scan your computer and then display  these files as  infections,  but will not allow you to remove them until  you purchase  the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%\MSE.ico</li>
<li>%AllUsersProfile%\Application Data\%random%\MSf4c.exe</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\My Security Engine.lnk</li>
<li>%UserProfile%\Application Data\My Security Engine\cookies.sqlite</li>
<li>%UserProfile%\Application Data\My Security Engine\Instructions.ini</li>
<li>%UserProfile%\Desktop\My Security Engine.lnk</li>
<li>%UserProfile%\Recent\snl2w.dll</li>
<li>%UserProfile%\Recent\snl2w.drv</li>
<li>%UserProfile%\Recent\std.exe</li>
<li>%UserProfile%\Recent\std.tmp</li>
<li>%UserProfile%\Recent\cid.tmp</li>
<li>%UserProfile%\Recent\DBOLE.tmp</li>
<li>%UserProfile%\Recent\eb.dll</li>
<li>%UserProfile%\Recent\eb.tmp</li>
<li>%UserProfile%\Recent\energy.exe</li>
<li>%UserProfile%\Recent\exec.sys</li>
<li>%UserProfile%\Recent\fix.dll</li>
<li>%UserProfile%\Recent\fix.drv</li>
<li>%UserProfile%\Recent\FW.exe</li>
<li>%UserProfile%\Recent\pal.drv</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\runddlkey.sys</li>
<li>%UserProfile%\Start Menu\My Security Engine.lnk</li>
<li>%UserProfile%\Start Menu\Programs\My Security Engine.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[1].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[2].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[3].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[4].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[5].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msfwsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OcHealthMon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WinSSUI.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;My Security Engine&#8221;</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>127.0.0.1       localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
<li>209.212.147.138 www.google.com</li>
<li>209.212.147.138 google.com</li>
<li>209.212.147.138 google.com.au</li>
<li>209.212.147.138 www.google.com.au</li>
<li>209.212.147.138 google.be</li>
<li>209.212.147.138 www.google.be</li>
<li>209.212.147.138 google.com.br</li>
<li>209.212.147.138 www.google.com.br</li>
<li>209.212.147.138 google.ca</li>
<li>209.212.147.138 www.google.ca</li>
<li>209.212.147.138 google.ch</li>
<li>209.212.147.138 www.google.ch</li>
<li>209.212.147.138 google.de</li>
<li>209.212.147.138 www.google.de</li>
<li>209.212.147.138 google.dk</li>
<li>209.212.147.138 www.google.dk</li>
<li>209.212.147.138 google.fr</li>
<li>209.212.147.138 www.google.fr</li>
<li>209.212.147.138 google.ie</li>
<li>209.212.147.138 www.google.ie</li>
<li>209.212.147.138 google.it</li>
<li>209.212.147.138 www.google.it</li>
<li>209.212.147.138 google.co.jp</li>
<li>209.212.147.138 www.google.co.jp</li>
<li>209.212.147.138 google.nl</li>
<li>209.212.147.138 www.google.nl</li>
<li>209.212.147.138 google.no</li>
<li>209.212.147.138 www.google.no</li>
<li>209.212.147.138 google.co.nz</li>
<li>209.212.147.138 www.google.co.nz</li>
<li>209.212.147.138 google.pl</li>
<li>209.212.147.138 www.google.pl</li>
<li>209.212.147.138 google.se</li>
<li>209.212.147.138 www.google.se</li>
<li>209.212.147.138 google.co.uk</li>
<li>209.212.147.138 www.google.co.uk</li>
<li>209.212.147.138 google.co.za</li>
<li>209.212.147.138 www.google.co.za</li>
<li>209.212.147.138 www.google-analytics.com</li>
<li>209.212.147.138 www.bing.com</li>
<li>209.212.147.138 search.yahoo.com</li>
<li>209.212.147.138 www.search.yahoo.com</li>
<li>209.212.147.138 uk.search.yahoo.com</li>
<li>209.212.147.138 ca.search.yahoo.com</li>
<li>209.212.147.138 de.search.yahoo.com</li>
<li>209.212.147.138 fr.search.yahoo.com</li>
<li>209.212.147.138 au.search.yahoo.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_1.png"><img class="alignnone size-medium wp-image-842" title="Adware.Win32.MySecurityEngine" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_1-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_2.png"><img class="alignnone size-medium wp-image-843" title="Adware.Win32.MySecurityEngine" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_3.png"><img class="alignnone size-medium wp-image-844" title="Adware.Win32.MySecurityEngine" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.MySecurityEngine_3-400x205.png" alt="" width="400" height="205" /></a></p>
<p><strong>How to remove the infection of My Security Engine</strong><strong> </strong><strong>(Adware.Win32.MySecurityEngine</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all  detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 15:09:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DigitalProtection]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=830</guid>
		<description><![CDATA[The Emsi Software malware research team has        discoverd a new outbreak           of the Digital Protection adware. Emsisoft                  Anti-Malware detects this malware [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has        discoverd a new outbreak           of the <strong>Digital Protection </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                  Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank">Adware.Win32.DigitalProtection</a></strong>.</p>
<p><strong>Digital Protection </strong>is a rogue security program. This is   a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank"><strong>Your Protection</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue     application      tries to trick you  by displaying  false       positive/misleading  scan     results  report, which  says that your        computer is infected with      viruses or  trojan, but you  will not   be     able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Digital Protection\dighook.dll</li>
<li>%ProgramFiles%\Digital Protection\digprot.exe</li>
<li>%ProgramFiles%\Digital Protection\help.ico</li>
<li>%ProgramFiles%\Digital Protection\scan.ico</li>
<li>%ProgramFiles%\Digital Protection\settings.ico</li>
<li>%ProgramFiles%\Digital Protection\splash.mp3</li>
<li>%ProgramFiles%\Digital Protection\Uninstall.exe</li>
<li>%ProgramFiles%\Digital Protection\update.ico</li>
<li>%ProgramFiles%\Digital Protection\virus.mp3</li>
<li>%ProgramFiles%\Digital Protection\about.ico</li>
<li>%ProgramFiles%\Digital Protection\activate.ico</li>
<li>%ProgramFiles%\Digital Protection\buy.ico</li>
<li>%ProgramFiles%\Digital Protection\dig.db</li>
<li>%ProgramFiles%\Digital Protection\digext.dll</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Digital Protection.lnk</li>
<li>%UserProfile%\Desktop\Digital Protection Support.lnk</li>
<li>%UserProfile%\Desktop\Digital Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Digital Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Digital Protection Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Digital Protection\Buy.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Digital Protection</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Digital Protection</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Digital Protection&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_1.png"><img class="alignnone size-medium wp-image-831" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_2.png"><img class="alignnone size-medium wp-image-832" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_3.png"><img class="alignnone size-medium wp-image-833" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_3-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_4.png"><img class="alignnone size-medium wp-image-834" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_4-400x314.png" alt="" width="400" height="314" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_5.png"><img class="alignnone size-medium wp-image-835" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_5-400x201.png" alt="" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_6.png"><img class="alignnone size-full wp-image-836" title="Adware.Win32.DigitalProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.DigitalProtection_6.png" alt="" width="337" height="118" /></a></p>
<p><strong>How to remove the infection of Digital Protection</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>DigitalProtection</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                 Anti-Malware</a></strong>. Run a full scan on all drives and    move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Suite Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 09:02:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntivirusSuite]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=825</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak    of the Antivirus Suite adware. Emsisoft    Anti-Malware detects this malware as Adware.Win32.AntivirusSoft.
Antivirus Suite is a rogue security program, this is a new variant from Antivirus Soft. A rogue  application  tries to trick you by displaying  [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has discoverd a new outbreak    of the <strong>Antivirus Suite</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft    Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSuite" target="_blank">Adware.Win32.AntivirusSoft</a></strong>.</p>
<p><strong>Antivirus Suite</strong> is a rogue security program, this is a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSoft" target="_blank"><strong>Antivirus Soft</strong></a>. A rogue  application  tries to trick you by displaying  false positive/misleading  scan results  report, which says that your  computer is infected with  viruses or  trojan, but you will not be able  to delete them before you  purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%\%random%.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\avsoft</li>
<li>HKEY_LOCAL_MACHINE\software\avsuite</li>
<li>HKEY_CURRENT_USER\software\avsoft</li>
<li>HKEY_CURRENT_USER\software\avsuite</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntivirusSuite_1.png"><img class="alignnone size-full wp-image-826" title="Adware.Win32.AntivirusSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntivirusSuite_1.png" alt="" width="332" height="133" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntivirusSuite_2.png"><img class="alignnone size-medium wp-image-827" title="Adware.Win32.AntivirusSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntivirusSuite_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><strong>How to remove the infection of Antivirus Suite </strong><strong>(Adware.Win32.</strong><strong>AntivirusSuite</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a>. Run a full scan on all drives and move all detected      items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivir Solution Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Control Components Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 07:36:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ControlComponents]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=819</guid>
		<description><![CDATA[The Emsi Software malware research team has          discoverd a new outbreak           of the Control Components adware.      a-squared               [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has          discoverd a new outbreak           of the <strong>Control Components </strong>adware.      <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                    Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlComponents" target="_blank"><strong>Adware.Win32.ControlComponents</strong></a>.</p>
<p><strong>Control Components </strong>is a rogue security program, this is a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ControlCenter" target="_blank"><strong>Control Center</strong></a>.  A  rogue   application         tries to trick you  by displaying  false      positive/misleading   scan       results  report, which  says that your       computer is  infected  with       viruses or  trojan, but you   will not be     able   to delete  them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Control Components\settings.ini</li>
<li>%UserProfile%\Application Data\Control Components\uninstall.exe</li>
<li>%UserProfile%\Application Data\Control Components\ccagent.exe</li>
<li>%UserProfile%\Application Data\Control Components\ccmain.exe</li>
<li>%UserProfile%\Application Data\Control Components\faq\guide.html</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\06.png</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\07.png</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\08.png</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\09.png</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\10.png</li>
<li>%UserProfile%\Application Data\Control Components\faq\images\05.png</li>
<li>%UserProfile%\Desktop\Control Components.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Control  Components</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run  &#8220;ccagent.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_1.png"><img class="alignnone size-medium wp-image-820" title="Adware.Win32.ControlComponents" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_1-400x276.png" alt="" width="400" height="276" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_2.png"><img class="alignnone size-medium wp-image-821" title="Adware.Win32.ControlComponents" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_2-351x400.png" alt="" width="351" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_3.png"><img class="alignnone size-medium wp-image-822" title="Adware.Win32.ControlComponents" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.ControlComponents_3-400x268.png" alt="" width="400" height="268" /></a></p>
<p><strong>How to remove the infection of Control Components </strong><strong>(Adware.Win32.ControlComponents</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                    Anti-Malware</a></strong>. Run a full scan on all drives  and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeCopyright Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/30/spyeraser-adware-removal-instructions/" rel="bookmark" class="crp_title">SpyEraser Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antimalware Doctor Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/08/antimalware-doctor-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/08/antimalware-doctor-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 19:21:55 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntimalwareDoctor]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=812</guid>
		<description><![CDATA[The Emsi Software malware research team has         discoverd a new outbreak           of the Antimalware Doctor adware.     a-squared                 [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has         discoverd a new outbreak           of the <strong>Antimalware Doctor </strong>adware.     <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                   Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntimalwareDoctor" target="_blank"><strong>Adware.Win32.AntimalwareDoctor</strong></a>.</p>
<p><strong>Antimalware Doctor </strong>is a rogue security program.  A rogue   application         tries to trick you  by displaying  false     positive/misleading   scan       results  report, which  says that your      computer is  infected  with       viruses or  trojan, but you  will not be     able   to delete  them  before you      purchase.</p>
<p><strong>Files:</strong></p>
<ul>
<li>%random%\enemies-names.txt</li>
<li>%random%\hookdll.dll</li>
<li>%random%\Antimalware Doctor.exe (or random)</li>
</ul>
<p><strong>Registry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Antimalware Doctor Inc</li>
<li>HKEY_CURRENT_USER\software\Antimalware Doctor Inc\Antimalware Doctor</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Antimalware Doctor.exe&#8221; (or random)</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_1.png"><img class="alignnone size-medium wp-image-813" title="Adware.Win32.AntimalwareDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_1-400x271.png" alt="" width="400" height="271" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_2.png"><img class="alignnone size-medium wp-image-814" title="Adware.Win32.AntimalwareDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_2-399x283.png" alt="" width="399" height="283" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_3.png"><img class="alignnone size-full wp-image-815" title="Adware.Win32.AntimalwareDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_3.png" alt="" width="380" height="129" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_4.png"><img class="alignnone size-medium wp-image-816" title="Adware.Win32.AntimalwareDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_4-400x368.png" alt="" width="400" height="368" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_5.png"><img class="alignnone size-medium wp-image-817" title="Adware.Win32.AntimalwareDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.AntimalwareDoctor_5-400x202.png" alt="" width="400" height="202" /></a></p>
<p><strong>How to remove the infection of Antimalware Doctor </strong><strong>(Adware.Win32.</strong><strong>AntimalwareDoctor</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                   Anti-Malware</a></strong>. Run a full scan on all drives and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/08/antimalware-doctor-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 20:01:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[YourProtection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=803</guid>
		<description><![CDATA[The Emsi Software malware research team has       discoverd a new outbreak           of the Your Protection adware.   a-squared                 Anti-Malware detects this malware [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has       discoverd a new outbreak           of the <strong>Your Protection </strong>adware.   <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                 Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank">Adware.Win32.YourProtection</a></strong>.</p>
<p><strong>Your Protection </strong>is a rogue security program. This is  a new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong> / <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>/<strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue    application      tries to trick you  by displaying  false      positive/misleading  scan     results  report, which  says that your       computer is infected with      viruses or  trojan, but you  will not  be     able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Your Protection\help.ico</li>
<li>%ProgramFiles%\Your Protection\scan.ico</li>
<li>%ProgramFiles%\Your Protection\settings.ico</li>
<li>%ProgramFiles%\Your Protection\splash.mp3</li>
<li>%ProgramFiles%\Your Protection\Uninstall.exe</li>
<li>%ProgramFiles%\Your Protection\update.ico</li>
<li>%ProgramFiles%\Your Protection\urp.db</li>
<li>%ProgramFiles%\Your Protection\urpext.dll</li>
<li>%ProgramFiles%\Your Protection\urphook.dll</li>
<li>%ProgramFiles%\Your Protection\urpprot.exe</li>
<li>%ProgramFiles%\Your Protection\virus.mp3</li>
<li>%ProgramFiles%\Your Protection\about.ico</li>
<li>%ProgramFiles%\Your Protection\activate.ico</li>
<li>%ProgramFiles%\Your Protection\buy.ico</li>
<li>%AllUsersProfile%\Desktop\nudetube.com.lnk</li>
<li>%AllUsersProfile%\Desktop\pornotube.com.lnk</li>
<li>%AllUsersProfile%\Desktop\youporn.com.lnk</li>
<li>%AllUsersProfile%\Favorites\_favdata.dat</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Protection.lnk</li>
<li>%UserProfile%\Desktop\Your Protection.lnk</li>
<li>%UserProfile%\Desktop\Your Protection Support.lnk</li>
<li>%UserProfile%\Local Settings\Temp\mplay32xe.exe</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Your Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Your Protection Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your Protection\Buy.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Your Protection</li>
<li>HKEY_LOCAL_MACHINE\software\Your Protection</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;mplay32xe.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Your Protection&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_1.png"><img class="alignnone size-medium wp-image-804" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_2.png"><img class="alignnone size-medium wp-image-805" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_3.png"><img class="alignnone size-medium wp-image-806" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_3-399x300.png" alt="" width="399" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_5.png"><img class="alignnone size-medium wp-image-807" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_5-400x201.png" alt="" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_6.png"><img class="alignnone size-medium wp-image-808" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_6-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_7.png"><img class="alignnone size-medium wp-image-809" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_8.png"><img class="alignnone size-full wp-image-810" title="Adware.Win32.YourProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.YourProtection_8.png" alt="" width="328" height="108" /></a></p>
<p><strong>How to remove the infection of Your Protection</strong><strong> </strong><strong>(Adware.Win32.YourProtection</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                Anti-Malware</a></strong>. Run a full scan on all drives and   move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User Antivirus 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 19:41:14 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[UserAntivirus2010]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=795</guid>
		<description><![CDATA[The Emsi Software malware research team has        discoverd a new outbreak           of the User Antivirus 2010 adware.    a-squared                  [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has        discoverd a new outbreak           of the <strong>User Antivirus 2010 </strong>adware.    <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                  Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserAntivirus2010" target="_blank"><strong>Adware.Win32.UserAntivirus2010</strong></a>.</p>
<p><strong>UserAntivirus2010 </strong>is a rogue security program, come from hxxp://userantivirus2010pro.yolasite. com.  A rogue   application        tries to trick you  by displaying  false     positive/misleading  scan       results  report, which  says that your      computer is infected  with       viruses or  trojan, but you  will not be     able  to delete  them  before you      purchase.</p>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_1.png"><img class="alignnone size-medium wp-image-796" title="Adware.Win32.UserAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_1-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_2.png"><img class="alignnone size-medium wp-image-797" title="Adware.Win32.UserAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_2-400x327.png" alt="" width="400" height="327" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_3.png"><img class="alignnone size-medium wp-image-798" title="Adware.Win32.UserAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_4.png"><img class="alignnone size-medium wp-image-799" title="Adware.Win32.UserAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_4-334x400.png" alt="" width="334" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_5.png"><img class="alignnone size-full wp-image-800" title="Adware.Win32.UserAntivirus2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/04/Adware.Win32.UserAntivirus2010_5.png" alt="" width="367" height="95" /></a></p>
<p><strong>How to remove the infection of User Antivirus 2010 </strong><strong>(Adware.Win32.UserAntivirus2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                  Anti-Malware</a></strong>. Run a full scan on all drives and     move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 19:31:55 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[UserProtection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=787</guid>
		<description><![CDATA[The Emsi Software malware research team has      discoverd a new outbreak           of the User Protection adware.  a-squared                Anti-Malware detects this malware as Adware.Win32.UserProtection.
User Protection [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has      discoverd a new outbreak           of the <strong>User Protection </strong>adware.  <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">Adware.Win32.UserProtection</a></strong>.</p>
<p><strong>User Protection </strong>is a rogue security program. This is a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard</strong></a>/<strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue   application      tries to trick you  by displaying  false     positive/misleading  scan     results  report, which  says that your      computer is infected with      viruses or  trojan, but you  will not be     able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\User Protection\scan.ico</li>
<li>%ProgramFiles%\User Protection\settings.ico</li>
<li>%ProgramFiles%\User Protection\splash.mp3</li>
<li>%ProgramFiles%\User Protection\uninstall.exe</li>
<li>%ProgramFiles%\User Protection\update.ico</li>
<li>%ProgramFiles%\User Protection\usr.db</li>
<li>%ProgramFiles%\User Protection\usrext.dll</li>
<li>%ProgramFiles%\User Protection\usrhook.dll</li>
<li>%ProgramFiles%\User Protection\usrprot.exe</li>
<li>%ProgramFiles%\User Protection\virus.mp3</li>
<li>%ProgramFiles%\User Protection\about.ico</li>
<li>%ProgramFiles%\User Protection\activate.ico</li>
<li>%ProgramFiles%\User Protection\buy.ico</li>
<li>%ProgramFiles%\User Protection\help.ico</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\User Protection.lnk</li>
<li>%UserProfile%\Desktop\User Protection.lnk</li>
<li>%UserProfile%\Desktop\User Protection Support.lnk</li>
<li>%UserProfile%\Desktop\License.txt</li>
<li>%UserProfile%\Local Settings\Temp\4otjesjty.mof</li>
<li>%UserProfile%\Local Settings\Temp\usr.dat</li>
<li>%UserProfile%\Local Settings\Temp\usrr.dat</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\User Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\User Protection Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\Buy.lnk</li>
<li>%UserProfile%\Start Menu\Programs\User Protection\Scan.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\User Protection</li>
<li>HKEY_LOCAL_MACHINE\software\User Protection</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;User Protection&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_1.png"><img class="alignnone size-medium wp-image-788" title="Adware.Win32.UserProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_2.png"><img class="alignnone size-medium wp-image-789" title="Adware.Win32.UserProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_3.png"><img class="alignnone size-medium wp-image-790" title="Adware.Win32.UserProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_3-400x131.png" alt="" width="400" height="131" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_4.png"><img class="alignnone size-medium wp-image-791" title="Adware.Win32.UserProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_4-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_5.png"><img class="alignnone size-medium wp-image-792" title="Adware.Win32.UserProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.UserProtection_5-400x274.png" alt="" width="400" height="274" /></a></p>
<p><strong>How to remove the infection of User Protection</strong><strong> </strong><strong>(Adware.Win32.UserProtection</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared               Anti-Malware</a></strong>. Run a full scan on all drives and  move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CleanUP Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 18:58:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[CleanUPAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=782</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak            of the CleanUP Antivirus adware. a-squared            Anti-Malware detects this malware as Adware.Win32.CleanUPAntivirus.
CleanUP Antivirus is a rogue security software that show false  [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak            of the <strong>CleanUP Antivirus</strong> adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared            Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CleanUPAntivirus" target="_blank">Adware.Win32.CleanUPAntivirus</a>.</p>
<p><strong>CleanUP Antivirus</strong> is a rogue security software that show false  warning  messages and show misleading scan results. It will start  automatically when your computer starts. The  installer will also create  numerous harmless files on your computer,  usually at Recent folder,  that are used to impersonate malware files.  Once the program is running  it will scan your computer and then display  these files as infections,  but will not allow you to remove them until  you purchase the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\58969\CUf4c.exe</li>
<li>%AllUsersProfile%\Application Data\58969\CUA.ico</li>
<li>%AllUsersProfile%\Application Data\CUQKWA\CUZNJUENEA.cfg</li>
<li>%UserProfile%\Application Data\CleanUp Antivirus\Instructions.ini</li>
<li>%UserProfile%\Application Data\CleanUp Antivirus\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Desktop\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\CleanUp Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;CleanUp Antivirus</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>127.0.0.1       localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_1.png"><img class="alignnone size-medium wp-image-783" title="Adware.Win32.CleanUPAntivirus_1" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_1-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_2.png"><img class="alignnone size-medium wp-image-784" title="Adware.Win32.CleanUPAntivirus_2" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><strong>How to remove the infection of CleanUP Antivirus</strong><strong> </strong><strong>(Adware.Win32.CleanUPAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared           Anti-Malware</a>. Run a full scan on all drives and move all detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SystemIron Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 23:35:28 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SystemIron]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=769</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak          of the SystemIron adware. a-squared          Anti-Malware detects this malware as Adware.Win32.SystemIron.
SystemIron is a rogue     security      program. This [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has discoverd a new outbreak          of the <strong>SystemIron</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared          Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemIron" target="_blank">Adware.Win32.SystemIron</a></strong>.</p>
<p><strong>SystemIron</strong> is a rogue     security      program. This is a new variant from Winiguard/Winisoft    family.  The      author of SystemIron also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurePcAv" target="_blank">SecurePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafePcAv" target="_blank">SafePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">GuardWWW</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>,… etc. To further convince victim, SystemIron will also create numerous junk files with random names on         your  computer that will be detected as malware when the program    scans      your  computer, but will not allow you to remove them until    you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SystemIron Software\SystemIron\data.bin</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\license.txt</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\main_config.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\SystemIron.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\SystemIronSvc.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\uninstall.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\always_delete.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\always_skip.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\SystemIron.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\1 SystemIron.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SystemIron</li>
<li>HKEY_LOCAL_MACHINE\software\SystemIron</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntispySvc</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemIronSvc</li>
<li>HKEY_CURRENT_USER\software\SystemIron</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SystemIron&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SystemIron&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_1.png"><img class="alignnone size-medium wp-image-770" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_2.png"><img class="alignnone size-medium wp-image-771" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_3.png"><img class="alignnone size-medium wp-image-772" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_4.png"><img class="alignnone size-medium wp-image-773" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_5.png"><img class="alignnone size-medium wp-image-774" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_6.png"><img class="alignnone size-medium wp-image-775" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_7.png"><img class="alignnone size-medium wp-image-776" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_7-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_8.png"><img class="alignnone size-medium wp-image-777" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_8-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_9.png"><img class="alignnone size-medium wp-image-778" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_9-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_10.png"><img class="alignnone size-medium wp-image-779" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_10-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_11.png"><img class="alignnone size-medium wp-image-780" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_11-400x273.png" alt="" width="400" height="273" /></a></p>
<p><strong>How to remove the infection of </strong><strong>SystemIron</strong><strong> </strong><strong>(Adware.Win32.SystemIron</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a>. Run a full scan on all drives and move all detected      items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus7 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/13/antivirus7-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/13/antivirus7-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 23:11:17 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Antivirus7]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=763</guid>
		<description><![CDATA[The Emsi Software malware research team has       discoverd a new outbreak           of the Antivirus7 adware.   a-squared                 Anti-Malware detects this malware as [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has       discoverd a new outbreak           of the <strong>Antivirus7 </strong>adware.   <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                 Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirus7" target="_blank"><strong>Adware.Win32.</strong><strong>Antivirus7</strong></a>.</p>
<p><strong>Antivirus7</strong> is a rogue security program clone of <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeAntivir" target="_blank">FakeAntivir</a></strong>, which is also a rogue  application that has become widespread.  A rogue   application       tries to trick you  by displaying  false     positive/misleading  scan      results  report, which  says that your      computer is infected with       viruses or  trojan, but you  will not be     able  to delete them  before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\AV7\antivirus7.exe</li>
<li>%SystemRoot%\system32\UpdateExplorer.dll</li>
<li>%AllUsersProfile%\Start Menu\AV7\Antivirus7.lnk</li>
<li>%AllUsersProfile%\Start Menu\AV7\Uninstall.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;AV7&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_5.png"><img class="alignnone size-medium wp-image-767" title="Adware.Win32.Antivirus7" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_5-400x240.png" alt="" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_2.png"><img class="alignnone size-medium wp-image-764" title="Adware.Win32.Antivirus7" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_2-400x278.png" alt="" width="400" height="278" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_3.png"><img class="alignnone size-medium wp-image-765" title="Adware.Win32.Antivirus7" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_3-400x240.png" alt="" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_4.png"><img class="alignnone size-medium wp-image-766" title="Adware.Win32.Antivirus7" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.Antivirus7_4-400x310.png" alt="" width="400" height="310" /></a></p>
<p><strong>How to remove the infection of Antivirus7</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>Antivirus7</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                 Anti-Malware</a></strong>. Run a full scan on all drives and    move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/07/07/antivirusgt-adware-removal-instructions/" rel="bookmark" class="crp_title">AntivirusGT Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/13/antivirus7-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Security Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 20:16:36 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SmartSecurity]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=754</guid>
		<description><![CDATA[The Emsi Software malware research team has      discoverd a new outbreak           of the Smart Security adware.  a-squared                Anti-Malware detects this malware as Adware.Win32.SmartSecurity.
Smart Security [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has      discoverd a new outbreak           of the <strong>Smart Security </strong>adware.  <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartSecurity" target="_blank">Adware.Win32.SmartSecurity</a></strong>.</p>
<p><strong>Smart Security</strong> is a rogue security program clone of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityTool" target="_blank"><strong>SecurityTool</strong></a>, which is also a rogue application that has become widespread.  A rogue   application      tries to trick you  by displaying  false     positive/misleading  scan     results  report, which  says that your      computer is infected with      viruses or  trojan, but you  will not be     able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Smart Security\SmartSecurity.exe</li>
<li>%ProgramFiles%\Smart Security\unins000.dat</li>
<li>%ProgramFiles%\Smart Security\unins000.exe</li>
<li>%ProgramFiles%\Smart Security\SmartSecurity.cfg</li>
<li>%AllUsersProfile%\Desktop\Smart Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Smart Security\Удалить Smart Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Smart Security\Smart Security.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Smart Security_is1</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SmartSecurity&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SmartSecurity&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_1.png"><img class="alignnone size-medium wp-image-755" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_1-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_2.png"><img class="alignnone size-medium wp-image-756" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_2-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_3.png"><img class="alignnone size-medium wp-image-757" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_3-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_4.png"><img class="alignnone size-medium wp-image-758" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_4-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_5.png"><img class="alignnone size-medium wp-image-759" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_5-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_6.png"><img class="alignnone size-medium wp-image-760" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_6-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_7.png"><img class="alignnone size-medium wp-image-761" title="Adware.Win32.SmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SmartSecurity_7-400x297.png" alt="" width="400" height="297" /></a></p>
<p><strong>How to remove the infection of Smart Security</strong><strong> </strong><strong>(Adware.Win32.SmartSecurity</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                Anti-Malware</a></strong>. Run a full scan on all drives and   move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/22/desktop-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Security 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/08/virus-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/08/virus-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 21:15:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[VirusProtector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=746</guid>
		<description><![CDATA[The Emsi Software malware research team has      discoverd a new outbreak           of the Virus Protector adware.  a-squared                Anti-Malware detects this malware as Adware.Win32.VirusProtector.
VirusProtector is [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has      discoverd a new outbreak           of the <strong>Virus Protector </strong>adware.  <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared                Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.VirusProtector" target="_blank">Adware.Win32.VirusProtector</a></strong>.</p>
<p><strong>VirusProtector</strong> is a rogue    security       program. Virus Protector create numerous harmless files with random names on         your  computer that will be detected as malware when the program    scans      your  computer, but will not allow you to remove them until    you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\%random%.exe</li>
<li>%SystemRoot%\%random%.dll</li>
<li>%SystemRoot%\system32\%random%.exe</li>
<li>%SystemRoot%\system32\%random%.dll</li>
<li>%SystemRoot%\system32\drivers\%random%.exe</li>
<li>%SystemRoot%\system32\drivers\%random%.dll</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Windows\LoadAppInit_DLLs, 0&#215;00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Windows\AppInit_DLLs, %random%.dll</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Shell, %random%.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_1.png"><img class="alignnone size-full wp-image-747" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_1.png" alt="" width="344" height="222" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_2.png"><img class="alignnone size-medium wp-image-748" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_2-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_3.png"><img class="alignnone size-full wp-image-749" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_3.png" alt="" width="386" height="222" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_4.png"><img class="alignnone size-medium wp-image-750" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_4-238x400.png" alt="" width="238" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_5.png"><img class="alignnone size-medium wp-image-751" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_5-400x203.png" alt="" width="400" height="203" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_6.png"><img class="alignnone size-full wp-image-752" title="Adware.Win32.VirusProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.VirusProtector_6.png" alt="" width="289" height="222" /></a></p>
<p><strong>How to remove the infection of Virus Protector</strong><strong> </strong><strong>(Adware.Win32.VirusProtector</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared               Anti-Malware</a></strong>. Run a full scan on all drives and  move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/08/antimalware-doctor-adware-removal-instructions/" rel="bookmark" class="crp_title">Antimalware Doctor Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/22/desktop-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Security 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/08/virus-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dr. Guard Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/03/dr-guard-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/03/dr-guard-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 19:21:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DrGuard]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=739</guid>
		<description><![CDATA[The Emsi Software malware research team has     discoverd a new outbreak           of the Dr. Guard adware. a-squared               Anti-Malware detects this malware as Adware.Win32.DrGuard.
Dr. Guard is a rogue [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has     discoverd a new outbreak           of the <strong>Dr. Guard </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared               Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank">Adware.Win32.DrGuard</a></strong>.</p>
<p><strong>Dr. Guard </strong>is a rogue security program.   This  rogue  application      tries to trick you  by displaying  false    positive/misleading  scan     results  report, which  says that your     computer is infected with      viruses or  trojan, but you  will not be    able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Dr. Guard\activate.ico</li>
<li>%ProgramFiles%\Dr. Guard\buy.ico</li>
<li>%ProgramFiles%\Dr. Guard\drg.db</li>
<li>%ProgramFiles%\Dr. Guard\drgext.dll</li>
<li>%ProgramFiles%\Dr. Guard\drghook.dll</li>
<li>%ProgramFiles%\Dr. Guard\drguard.exe</li>
<li>%ProgramFiles%\Dr. Guard\help.ico</li>
<li>%ProgramFiles%\Dr. Guard\scan.ico</li>
<li>%ProgramFiles%\Dr. Guard\settings.ico</li>
<li>%ProgramFiles%\Dr. Guard\splash.mp3</li>
<li>%ProgramFiles%\Dr. Guard\uninstall.exe</li>
<li>%ProgramFiles%\Dr. Guard\update.ico</li>
<li>%ProgramFiles%\Dr. Guard\virus.mp3</li>
<li>%ProgramFiles%\Dr. Guard\about.ico</li>
<li>%AllUsersProfile%\Desktop\License.txt</li>
<li>%UserProfile%\Desktop\Dr. Guard.lnk</li>
<li>%UserProfile%\Desktop\Dr. Guard Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Buy.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Dr. Guard.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Dr. Guard Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Dr. Guard\About.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Dr. Guard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Dr. Guard</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Dr. Guard&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_1.png"><img class="alignnone size-medium wp-image-740" title="Adware.Win32.DrGuard_1" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_2.png"><img class="alignnone size-medium wp-image-741" title="Adware.Win32.DrGuard_2" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_3.png"><img class="alignnone size-medium wp-image-742" title="Adware.Win32.DrGuard_3" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_3-400x131.png" alt="" width="400" height="131" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_4.png"><img class="alignnone size-medium wp-image-743" title="Adware.Win32.DrGuard_4" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_4-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_5.png"><img class="alignnone size-medium wp-image-744" title="Adware.Win32.DrGuard_5" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.DrGuard_5-400x274.png" alt="" width="400" height="274" /></a></p>
<p><strong>How to remove the infection of Dr. Guard</strong><strong> </strong><strong>(Adware.Win32.DrGuard</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared              Anti-Malware</a></strong>. Run a full scan on all drives and move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/your-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Your Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/03/dr-guard-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PC Defender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 22:58:42 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PCDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=727</guid>
		<description><![CDATA[The Emsi Software malware research team has    discoverd a new outbreak           of the PC Defender adware. a-squared              Anti-Malware detects this malware as Adware.Win32.PCDefender.
PC Defender is a rogue security program. [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has    discoverd a new outbreak           of the <strong>PC Defender</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared              Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCDefender" target="_blank">Adware.Win32.PCDefender</a></strong>.</p>
<p><strong>PC Defender </strong>is a rogue security program.   This rogue  application      tries to trick you  by displaying  false   positive/misleading  scan     results  report, which  says that your    computer is infected with      viruses or  trojan, but you  will not be   able  to delete them before you      purchase.</p>
<p>This program has a funny thing. It will displays fake blue screen on the victim machine. The blue screen will look like this:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_1.png"><img class="alignnone size-medium wp-image-728" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_1-400x203.png" alt="" width="400" height="203" /></a></p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Def Group\PC Defender\Antispyware.exe</li>
<li>%ProgramFiles%\Def Group\PC Defender\hook.dll</li>
<li>%ProgramFiles%\Def Group\PC Defender\proccheck.exe</li>
<li>%AllUsersProfile%\Desktop\PC Defender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PC Defender\PC Defender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Def Group</li>
<li>HKEY_CURRENT_USER\software\Def Group\Antispyware</li>
<li>HKEY_CURRENT_USER\software\Def Group\Antispyware\Found</li>
</ul>
<p><strong>Modify registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon<br />
Old: Userinit = C:\WINDOWS\system32\userinit.exe,<br />
New: Userinit = C:\WINDOWS\system32\userinit.exe,&#8221;C:\Program Files\Def Group\PC Defender\Antispyware.exe&#8221;</li>
</ul>
<p>Screenshots:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_2.png"><img class="alignnone size-medium wp-image-729" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_2-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_3.png"><img class="alignnone size-medium wp-image-730" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_3-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_4.png"><img class="alignnone size-medium wp-image-731" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_4-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_5.png"><img class="alignnone size-medium wp-image-732" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_5-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_6.png"><img class="alignnone size-medium wp-image-733" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_6-400x307.png" alt="" width="400" height="307" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_7.png"><img class="alignnone size-medium wp-image-734" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_7-400x288.png" alt="" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_8.png"><img class="alignnone size-medium wp-image-735" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_8-400x288.png" alt="" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_9.png"><img class="alignnone size-medium wp-image-736" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_9-400x239.png" alt="" width="400" height="239" /></a></p>
<p><strong>How to remove the infection of PC Defender</strong><strong> </strong><strong>(Adware.Win32.PCDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared             Anti-Malware</a></strong>. Run a full scan on all drives and move    all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Advanced Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Total PC Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your PC Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 21:04:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[YourPCProtector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=719</guid>
		<description><![CDATA[The Emsi Software malware research team has   discoverd a new outbreak           of the Your PC Protector adware. a-squared             Anti-Malware detects this malware as Adware.Win32.YourPCProtector.
Your PC Protector  is a rogue security [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has   discoverd a new outbreak           of the Your PC Protector adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared             Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourPCProtector" target="_blank">Adware.Win32.YourPCProtector</a></strong>.</p>
<p><strong>Your PC Protector </strong> is a rogue security program.  This rogue  application      tries to trick you  by displaying  false  positive/misleading  scan     results  report, which  says that your   computer is infected with      viruses or  trojan, but you  will not be  able  to delete them before you      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\nuar.old</li>
<li>%ProgramFiles%\skynet.dat</li>
<li>%ProgramFiles%\svchost.exe</li>
<li>%ProgramFiles%\wp3.dat</li>
<li>%ProgramFiles%\wp4.dat</li>
<li>%ProgramFiles%\adc32.dll</li>
<li>%ProgramFiles%\alggui.exe</li>
<li>%ProgramFiles%\Your PC Protector\Your PC Protector.exe</li>
<li>%UserProfile%\Desktop\Your PC Protector.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Your PC Protector\Your PC Protector.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd</li>
<li>HKEY_CURRENT_USER\software\Your PC Protector</li>
<li>HKEY_CURRENT_USER\software\Your PC Protector\PC_protect</li>
<li>HKEY_CURRENT_USER\software\Your PC Protector\PC_protect\Registration</li>
<li>HKEY_CURRENT_USER\software\Your PC Protector\PC_protect\setdata</li>
</ul>
<p><strong>Modify registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\exefile\shell\open\command\, &#8220;C:\Program Files\alggui.exe &#8220;%1&#8243; %*&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_1.png"><img class="alignnone size-medium wp-image-720" title="Adware.Win32.YourPCProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_1-400x301.png" alt="" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_2.png"><img class="alignnone size-medium wp-image-721" title="Adware.Win32.YourPCProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_2-400x334.png" alt="" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_3.png"><img class="alignnone size-medium wp-image-722" title="Adware.Win32.YourPCProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.YourPCProtector_3-400x210.png" alt="" width="400" height="210" /></a></p>
<p><strong>How to remove the infection of Your PC Protector</strong><strong> </strong><strong>(Adware.Win32.YourPCProtector</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared            Anti-Malware</a></strong>. Run a full scan on all drives and move   all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/08/virus-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Virus Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Desktop Security 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/22/desktop-security-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/22/desktop-security-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 20:10:49 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DesktopSecurity2010]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=712</guid>
		<description><![CDATA[The Emsi Software malware research team has  discoverd a new outbreak           of the Desktop Security 2010 adware. a-squared            Anti-Malware detects this malware as Adware.Win32.DesktopSecurity2010.
Desktop Security 2010 is a rogue security program. This rogue [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has  discoverd a new outbreak           of the <strong>Desktop Security 2010</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared            Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DesktopSecurity2010" target="_blank">Adware.Win32.DesktopSecurity2010</a></strong>.</p>
<p><strong>Desktop Security 2010</strong> is a rogue security program. This rogue  application      tries to trick you  by displaying  false positive/misleading  scan     results  report, which  says that your  computer is infected with      viruses or  trojan, but you  will not be able  to delete them before you      purchase.</p>
<p><strong>Create new files (some files and registry name are random):</strong></p>
<ul>
<li>%ProgramFiles%\Desktop Security 2010\</li>
<li>%ProgramFiles%\Desktop Security 2010\MFC71ENU.DLL</li>
<li>%ProgramFiles%\Desktop Security 2010\msvcp71.dll</li>
<li>%ProgramFiles%\Desktop Security 2010\msvcr71.dll</li>
<li>%ProgramFiles%\Desktop Security 2010\pthreadVC2.dll</li>
<li>%ProgramFiles%\Desktop Security 2010\securitycenter.exe</li>
<li>%ProgramFiles%\Desktop Security 2010\taskmgr.dll</li>
<li>%ProgramFiles%\Desktop Security 2010\uninstall.exe</li>
<li>%ProgramFiles%\Desktop Security 2010\daily.cvd</li>
<li>%ProgramFiles%\Desktop Security 2010\Desktop Security 2010.exe</li>
<li>%ProgramFiles%\Desktop Security 2010\guide.chm</li>
<li>%ProgramFiles%\Desktop Security 2010\hjengine.dll</li>
<li>%ProgramFiles%\Desktop Security 2010\mfc71.dll</li>
<li>%SystemRoot%\system32\cbrdwlvrumw6.exe</li>
<li>%UserProfile%\Local Settings\Temp\kilslmd.exex</li>
<li>%UserProfile%\Local Settings\Temp\kn.a.exe</li>
<li>%UserProfile%\Local Settings\Temp\gedx_ae09.exe</li>
<li>%UserProfile%\Local Settings\Temp\kgn.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Desktop Security 2010</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Desktop Security 2010</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Desktop Security 2010&#8243;</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SecurityCenter&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;cbrdwlvrumw6&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_1.png"><img class="alignnone size-medium wp-image-713" title="Adware.Win32.DesktopSecurity2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_1-400x238.png" alt="" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_2.png"><img class="alignnone size-medium wp-image-714" title="Adware.Win32.DesktopSecurity2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_2-400x238.png" alt="" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_3.png"><img class="alignnone size-medium wp-image-715" title="Adware.Win32.DesktopSecurity2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_3-400x319.png" alt="" width="400" height="319" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_4.png"><img class="alignnone size-medium wp-image-716" title="Adware.Win32.DesktopSecurity2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_4-400x358.png" alt="" width="400" height="358" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_5.png"><img class="alignnone size-full wp-image-717" title="Adware.Win32.DesktopSecurity2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.DesktopSecurity2010_5.png" alt="" width="395" height="133" /></a></p>
<p><strong>How to remove the infection of Desktop Security 2010</strong><strong> </strong><strong>(Adware.Win32.DesktopSecurity2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared           Anti-Malware</a></strong>. Run a full scan on all drives and move  all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Essentials 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/22/desktop-security-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP Micro Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 20:02:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[XPMicroAntivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=700</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak           of the XP Micro Antivirus adware. a-squared           Anti-Malware detects this malware as Adware.Win32.XPMicroAntivirus.
XP Micro Antivirus is a rogue application. This rogue  application  [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has discoverd a new outbreak           of the <strong>XP Micro Antivirus</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared           Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XPMicroAntivirus" target="_blank">Adware.Win32.XPMicroAntivirus</a></strong>.</p>
<p>XP Micro Antivirus is a rogue application. This rogue  application     tries to trick you  by displaying  false positive/misleading  scan    results  report, which  says that your  computer is infected with     viruses or  trojan, but you  will not be able  to delete them before you     purchase.</p>
<p>We&#8217;ve found something interesting with this rogue. When we opened it using Hex Editor, we&#8217;ve found this string:</p>
<blockquote><p><strong>Congratulations, now you see this is just a ****ing rogue antivirus! Have a nice day!</strong></p></blockquote>
<p>As you can see on this picture:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_6.png"><img class="alignnone size-medium wp-image-701" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_6-400x217.png" alt="" width="400" height="217" /></a></p>
<p>If you want to see this message directly from the program, type &#8220;nocall122&#8243; as a Registration Email and Registration Key on the registration form :)</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_7.png"><img class="alignnone size-medium wp-image-704" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_7-400x296.png" alt="" width="400" height="296" /></a></p>
<p>Another screenshots:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_1.png"><img class="alignnone size-medium wp-image-705" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_1-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_2.png"><img class="alignnone size-full wp-image-706" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_2.png" alt="" width="263" height="319" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_3.png"><img class="alignnone size-medium wp-image-707" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_3-400x153.png" alt="" width="400" height="153" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_4.png"><img class="alignnone size-medium wp-image-708" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_4-400x397.png" alt="" width="400" height="397" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_5.png"><img class="alignnone size-medium wp-image-709" title="Adware.Win32.XPMicroAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPMicroAntivirus_5-400x251.png" alt="" width="400" height="251" /></a></p>
<p><strong>How to remove the infection of XP Micro Antivirus</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>XPMicroAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared          Anti-Malware</a></strong>. Run a full scan on all drives and move all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Essentials 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 16:29:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SecurityEssentials2010]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=692</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak  of the Security Essentials 2010 adware. a-squared  Anti-Malware detects this malware as  Adware.Win32.SecurityEssentials2010.
Security Essentials 2010 is a rogue scanner program. This is a new variant from Internet Security 2010 family. Once installed,  this application will be immediately perform scan action [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak  of the <strong>Security Essentials 2010</strong> adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a> detects this malware as  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityEssentials2010" target="_blank">Adware.Win32.SecurityEssentials2010</a>.</p>
<p>Security Essentials 2010 is a rogue scanner program. This is a new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurity2010" target="_blank">Internet Security 2010</a></strong> family. Once installed,  this application will be immediately perform scan action without prior  notice. This fake scanner application tries to trick you by displaying  misleading scan results report, which says that your computer is  infected with viruses or trojan, but you will not be able to delete them  before you buy this fraud application. Be careful with this program,  because it not going to protect your computer but will only spend your  money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Securityessentials2010\SE2010.exe</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security essentials 2010.lnk</li>
<li>%UserProfile%\Desktop\Security essentials 2010.lnk</li>
<li>%UserProfile%\Start Menu\Security essentials 2010.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\SE2010</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Security essentials 2010&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="../wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_5.png"><img title="Adware.Win32.SecurityEssentials2010" src="../wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_5-400x280.png" alt="" width="400" height="280" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_1.png"><img class="alignnone size-medium wp-image-693" title="Adware.Win32.SecurityEssentials2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_1-399x295.png" alt="" width="399" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_2.png"><img class="alignnone size-medium wp-image-694" title="Adware.Win32.SecurityEssentials2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_2-400x340.png" alt="" width="400" height="340" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_4.png"><img class="alignnone size-medium wp-image-696" title="Adware.Win32.SecurityEssentials2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_4-400x384.png" alt="" width="400" height="384" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_3.png"><img class="alignnone size-medium wp-image-695" title="Adware.Win32.SecurityEssentials2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityEssentials2010_3-400x240.png" alt="" width="400" height="240" /></a></p>
<p><strong>How to remove the infection  of </strong><strong>Security Essentials 2010 </strong><strong>(Adware.Win32.</strong><strong>SecurityEssentials2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a>. Run a full scan on all drives and move all detected  items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 15:25:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SecurityAntivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=684</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak           of the Security Antivirus adware. a-squared           Anti-Malware detects this malware as Adware.Win32.SecurityAntivirus.
Security Antivirus is a rogue security software that show false warning  messages [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak           of the Security Antivirus adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared           Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityAntivirus" target="_blank">Adware.Win32.SecurityAntivirus</a>.</p>
<p>Security Antivirus is a rogue security software that show false warning  messages and show misleading scan results. It will start automatically when your computer starts. The  installer will also create numerous harmless files on your computer,  usually at Recent folder, that are used to impersonate malware files.  Once the program is running it will scan your computer and then display  these files as infections, but will not allow you to remove them until  you purchase the program.</p>
<p><strong>Create new files (some file/directory are random):</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\58969\SAf4c.exe</li>
<li>%AllUsersProfile%\Application Data\58969\SAV.ico</li>
<li>%AllUsersProfile%\Application Data\SAPZUTPQV\SAJPV.cfg</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Antivirus.lnk</li>
<li>%UserProfile%\Application Data\Security Antivirus\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Security Antivirus\Instructions.ini</li>
<li>%UserProfile%\Desktop\Security Antivirus.lnk</li>
<li>%UserProfile%\Recent\DBOLE.drv</li>
<li>%UserProfile%\Recent\delfile.tmp</li>
<li>%UserProfile%\Recent\eb.sys</li>
<li>%UserProfile%\Recent\eb.tmp</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\FS.drv</li>
<li>%UserProfile%\Recent\FW.tmp</li>
<li>%UserProfile%\Recent\pal.tmp</li>
<li>%UserProfile%\Recent\ppal.drv</li>
<li>%UserProfile%\Recent\runddl.exe</li>
<li>%UserProfile%\Recent\SM.sys</li>
<li>%UserProfile%\Recent\snl2w.exe</li>
<li>%UserProfile%\Recent\std.dll</li>
<li>%UserProfile%\Recent\tjd.dll</li>
<li>%UserProfile%\Recent\ANTIGEN.tmp</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Start Menu\Security Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_67cbf[1].DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_67cbf[1].DocHostUIHandler\Clsid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Tracing\FWCFG</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[1].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[2].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[3].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[4].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[5].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msfwsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OcHealthMon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WinSSUI.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Security Antivirus&#8221;</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>127.0.0.1       localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
<li>94.228.209.235 www.google.com</li>
<li>94.228.209.235 google.com</li>
<li>94.228.209.235 google.com.au</li>
<li>94.228.209.235 www.google.com.au</li>
<li>94.228.209.235 google.be</li>
<li>94.228.209.235 www.google.be</li>
<li>94.228.209.235 google.com.br</li>
<li>94.228.209.235 www.google.com.br</li>
<li>94.228.209.235 google.ca</li>
<li>94.228.209.235 www.google.ca</li>
<li>94.228.209.235 google.ch</li>
<li>94.228.209.235 www.google.ch</li>
<li>94.228.209.235 google.de</li>
<li>94.228.209.235 www.google.de</li>
<li>94.228.209.235 google.dk</li>
<li>94.228.209.235 www.google.dk</li>
<li>94.228.209.235 google.fr</li>
<li>94.228.209.235 www.google.fr</li>
<li>94.228.209.235 google.ie</li>
<li>94.228.209.235 www.google.ie</li>
<li>94.228.209.235 google.it</li>
<li>94.228.209.235 www.google.it</li>
<li>94.228.209.235 google.co.jp</li>
<li>94.228.209.235 www.google.co.jp</li>
<li>94.228.209.235 google.nl</li>
<li>94.228.209.235 www.google.nl</li>
<li>94.228.209.235 google.no</li>
<li>94.228.209.235 www.google.no</li>
<li>94.228.209.235 google.co.nz</li>
<li>94.228.209.235 www.google.co.nz</li>
<li>94.228.209.235 google.pl</li>
<li>94.228.209.235 www.google.pl</li>
<li>94.228.209.235 google.se</li>
<li>94.228.209.235 www.google.se</li>
<li>94.228.209.235 google.co.uk</li>
<li>94.228.209.235 www.google.co.uk</li>
<li>94.228.209.235 google.co.za</li>
<li>94.228.209.235 www.google.co.za</li>
<li>94.228.209.235 www.google-analytics.com</li>
<li>94.228.209.235 www.bing.com</li>
<li>94.228.209.235 search.yahoo.com</li>
<li>94.228.209.235 www.search.yahoo.com</li>
<li>94.228.209.235 uk.search.yahoo.com</li>
<li>94.228.209.235 ca.search.yahoo.com</li>
<li>94.228.209.235 de.search.yahoo.com</li>
<li>94.228.209.235 fr.search.yahoo.com</li>
<li>94.228.209.235 au.search.yahoo.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_1.png"><img class="alignnone size-medium wp-image-685" title="Adware.Win32.SecurityAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_1-400x202.png" alt="" width="400" height="202" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_2.png"><img class="alignnone size-medium wp-image-686" title="Adware.Win32.SecurityAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_3.png"><img class="alignnone size-medium wp-image-687" title="Adware.Win32.SecurityAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_3-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_4.png"><img class="alignnone size-medium wp-image-688" title="Adware.Win32.SecurityAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_4-400x203.png" alt="" width="400" height="203" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_5.png"><img class="alignnone size-medium wp-image-689" title="Adware.Win32.SecurityAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurityAntivirus_5-400x283.png" alt="" width="400" height="283" /></a></p>
<p><strong>How to remove the infection of Security Antivirus</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>SecurityAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared          Anti-Malware</a>. Run a full scan on all drives and move all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP Antivirus Pro 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 16:58:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[XPAntivirusPro2010]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=675</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak          of the XP Antivirus Pro 2010 adware. a-squared          Anti-Malware detects this malware as Adware.Win32.XPAntivirusPro2010.
XP Antivirus Pro 2010 is a rogue application. This rogue  application  [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak          of the XP Antivirus Pro 2010 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared          Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XPAntivirusPro2010" target="_blank">Adware.Win32.XPAntivirusPro2010</a>.</p>
<p>XP Antivirus Pro 2010 is a rogue application. This rogue  application    tries to trick you  by displaying  false positive/misleading  scan   results  report, which  says that your  computer is infected with    viruses or  trojan, but you  will not be able  to delete them before you    purchase. This rogue will active every time user access a browser like Internet Explorer or Mozilla Firefox and will show you fake alert message.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\av.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\, &#8220;%UserProfile%\Local Settings\Application Data\av.exe&#8221; /START &#8220;%ProgramFiles%\Mozilla Firefox\firefox.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\, &#8220;%UserProfile%\Local Settings\Application Data\av.exe&#8221; /START &#8220;%ProgramFiles%\Mozilla Firefox\firefox.exe&#8221; -safe-mode</li>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\, &#8220;%UserProfile%\Local Settings\Application Data\av.exe&#8221; /START &#8220;%ProgramFiles%\Internet Explorer\iexplore.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_1.png"><img class="alignnone size-medium wp-image-676" title="Adware.Win32.XPAntivirusPro2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_1-400x283.png" alt="" width="400" height="283" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_2.png"><img class="alignnone size-medium wp-image-677" title="Adware.Win32.XPAntivirusPro2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_2-400x320.png" alt="" width="400" height="320" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_3.png"><img class="alignnone size-medium wp-image-678" title="Adware.Win32.XPAntivirusPro2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_3-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_4.png"><img class="alignnone size-medium wp-image-679" title="Adware.Win32.XPAntivirusPro2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_4-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_5.png"><img class="alignnone size-medium wp-image-680" title="Adware.Win32.XPAntivirusPro2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.XPAntivirusPro2010_5-400x264.png" alt="" width="400" height="264" /></a></p>
<p><strong>How to remove the infection of XP Antivirus Pro 2010</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>XPAntivirusPro2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared         Anti-Malware</a>. Run a full scan on all drives and move all detected         items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Win Antispyware Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecurePcAv Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 16:27:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SecurePcAv]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=661</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak         of the SecurePcAv adware. a-squared         Anti-Malware detects this malware as Adware.Win32.SecurePcAv.
SecurePcAv, come from hxxp://www.securepcav.com, is a rogue    security      program. This [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak         of the SecurePcAv adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared         Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurePcAv" target="_blank">Adware.Win32.SecurePcAv</a>.</p>
<p>SecurePcAv, come from hxxp://www.securepcav.com, is a rogue    security      program. This is a new variant from Winiguard/Winisoft   family.  The      author of SecurePcAv also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafePcAv" target="_blank">SafePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">GuardWWW</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>,… etc. To further convince victims  SecurePcAv, will also create numerous junk files with random names on        your  computer that will be detected as malware when the program   scans      your  computer, but will not allow you to remove them until   you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\always_skip.xml</li>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\main_config.xml</li>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\SecurePcAv.exe</li>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\uninstall.exe</li>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\always_delete.xml</li>
<li>%ProgramFiles%\SecurePcAv Software\SecurePcAv\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\SecurePcAv.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecurePcAv\1 SecurePcAv.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecurePcAv\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecurePcAv\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@securepcav[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SecurePcAv</li>
<li>HKEY_LOCAL_MACHINE\software\SecurePcAv</li>
<li>HKEY_CURRENT_USER\software\SecurePcAv</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SecurePcAv&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SecurePcAv&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_1.png"><img class="alignnone size-medium wp-image-662" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_2.png"><img class="alignnone size-full wp-image-663" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_3.png"><img class="alignnone size-medium wp-image-664" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_4.png"><img class="alignnone size-medium wp-image-665" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_5.png"><img class="alignnone size-medium wp-image-666" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_6.png"><img class="alignnone size-medium wp-image-667" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_7.png"><img class="alignnone size-medium wp-image-668" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_8.png"><img class="alignnone size-medium wp-image-669" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_9.png"><img class="alignnone size-medium wp-image-670" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_10.png"><img class="alignnone size-medium wp-image-671" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_11.png"><img class="alignnone size-medium wp-image-672" title="Adware.Win32.SecurePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SecurePcAv_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of SecurePcAv </strong><strong>(Adware.Win32.</strong><strong>SecurePcAv</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared     Anti-Malware</a>. Run a full scan on all drives and move all detected     items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemIron Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paladin Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 16:14:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PaladinAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=652</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak      of the Paladin Antivirus adware. a-squared      Anti-Malware detects this malware as Adware.Win32.PaladinAntivirus.
Paladin Antivirus is a rogue application. This rogue  application   tries to trick you  by displaying  false positive/misleading  [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak      of the Paladin Antivirus adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">Adware.Win32.PaladinAntivirus</a>.</p>
<p>Paladin Antivirus is a rogue application. This rogue  application   tries to trick you  by displaying  false positive/misleading  scan  results  report, which  says that your  computer is infected with   viruses or  trojan, but you  will not be able  to delete them before you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Paladin Antivirus\phook.dll</li>
<li>%ProgramFiles%\Paladin Antivirus\uninstall.exe</li>
<li>%ProgramFiles%\Paladin Antivirus\help.ico</li>
<li>%ProgramFiles%\Paladin Antivirus\pav.db</li>
<li>%ProgramFiles%\Paladin Antivirus\pav.exe</li>
<li>%ProgramFiles%\Paladin Antivirus\pavext.dll</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Paladin Antivirus.lnk</li>
<li>%UserProfile%\Desktop\Paladin Antivirus.lnk</li>
<li>%UserProfile%\Desktop\Paladin Antivirus Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Paladin Antivirus\Paladin Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Paladin Antivirus\Paladin Antivirus Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Paladin Antivirus\Uninstall Paladin Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus</li>
<li>HKEY_LOCAL_MACHINE\software\Paladin Antivirus</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Paladin Antivirus&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_1.png"><img class="alignnone size-medium wp-image-653" title="Adware.Win32.PaladinAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_1-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_2.png"><img class="alignnone size-medium wp-image-654" title="Adware.Win32.PaladinAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_2-400x185.png" alt="" width="400" height="185" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_3.png"><img class="alignnone size-medium wp-image-655" title="Adware.Win32.PaladinAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_3-400x131.png" alt="" width="400" height="131" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_4.png"><img class="alignnone size-medium wp-image-656" title="Adware.Win32.PaladinAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_4-400x296.png" alt="" width="400" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_8.png"><img class="alignnone size-full wp-image-657" title="Adware.Win32.PaladinAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PaladinAntivirus_8.png" alt="" width="258" height="346" /></a></p>
<p><strong>How to remove the infection of Paladin Antivirus</strong><strong></strong><strong> </strong><strong>(Adware.Win32.</strong><strong>PaladinAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared        Anti-Malware</a>. Run a full scan on all drives and move all detected        items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Defender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 15:58:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AdvancedDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=647</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak     of the Advanced Defender adware. a-squared     Anti-Malware detects this malware as Adware.Win32.AdvancedDefender.
Advanced Defender is a rogue application. This rogue  application  tries to trick you  by displaying  false positive/misleading  scan results  [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak     of the Advanced Defender adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared     Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdvancedDefender" target="_blank">Adware.Win32.AdvancedDefender</a>.</p>
<p>Advanced Defender is a rogue application. This rogue  application  tries to trick you  by displaying  false positive/misleading  scan results  report, which  says that your  computer is infected with  viruses or  trojan, but you  will not be able  to delete them before you  purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Advanced Defender\baseadd.wdb</li>
<li>%ProgramFiles%\Advanced Defender\conf.wcf</li>
<li>%ProgramFiles%\Advanced Defender\quarant.wdb</li>
<li>%ProgramFiles%\Advanced Defender\queue.wdb</li>
<li>%ProgramFiles%\Advanced Defender\advanceddefender.exe</li>
<li>%ProgramFiles%\Advanced Defender\base.wdb</li>
<li>%AllUsersProfile%\Microsoft PData\track.wid</li>
<li>%UserProfile%\Desktop\Advanced Defender.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Advanced Defender\Advanced Defender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Advanced Defender</li>
<li>HKEY_LOCAL_MACHINE\software\Advanced Defender\Soft</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Advanced Defender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;advanceddefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_2.png"><img class="alignnone size-medium wp-image-648" title="Adware.Win32.AdvancedDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_4.png"><img class="alignnone size-medium wp-image-649" title="Adware.Win32.AdvancedDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_4-400x343.png" alt="" width="400" height="343" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_5.png"><img class="alignnone size-full wp-image-650" title="Adware.Win32.AdvancedDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AdvancedDefender_5.png" alt="" width="338" height="300" /></a></p>
<p><strong>How to remove the infection of </strong><strong>Advanced Defender</strong><strong> </strong><strong>(Adware.Win32.AdvancedDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared       Anti-Malware</a>. Run a full scan on all drives and move all detected       items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Total PC Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/26/windows-system-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows System Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/14/windows-enterprise-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Enterprise Defender Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 18:04:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[FakeAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=636</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak    of the Fake Antivirus  adware. a-squared    Anti-Malware detects this malware as Adware.Win32.FakeAntivirus.
&#8220;Antivirus&#8221;, is name of this rogue application, it come from hxxp://just-protect-pc.info. This rogue  application  tries to trick you by displaying  false positive/misleading  scan [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak    of the Fake Antivirus  adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared    Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeAntivirus" target="_blank">Adware.Win32.FakeAntivirus</a>.</p>
<p>&#8220;Antivirus&#8221;, is name of this rogue application, it come from hxxp://just-protect-pc.info. This rogue  application  tries to trick you by displaying  false positive/misleading  scan results  report, which says that your  computer is infected with  viruses or  trojan, but you will not be able  to delete them before you  purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Antivirus\AvBho.dll</li>
<li>%ProgramFiles%\Antivirus\Uninstall.exe</li>
<li>%ProgramFiles%\Antivirus\wscsvc32.exe</li>
<li>%ProgramFiles%\Antivirus\Antivirus.exe</li>
<li>%AllUsersProfile%\Desktop\Antivirus.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Antivirus\Antivirus.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Antivirus\Uninstall.lnk</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk</li>
<li>%UserProfile%\Local Settings\Temp\winupd64x.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Antivirus</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp\CurVer</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp.1</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp.1\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\Programmable</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\VersionIndependentProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\0\win32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\FLAGS</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\HELPDIR</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d541c6a-573b-4888-b35e-6816e68c3620}</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Antivirus</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Antivirus.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;wscsvc32.exe&#8221;</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>174.142.113.204           just-protect-pc.info</li>
<li>70.38.11.165             review.2009softwarereviews.com</li>
<li>70.38.11.165             a1.review.zdnet.com</li>
<li>70.38.11.165             d1.reviews.cnet.com</li>
<li>70.38.11.165             reviews.toptenreviews.com</li>
<li>70.38.11.165             reviews.download.com</li>
<li>70.38.11.165             reviews.pcadvisor.co.uk</li>
<li>70.38.11.165             reviews.pcmag.com</li>
<li>70.38.11.165             reviews.pcpro.co.uk</li>
<li>70.38.11.165             reviews.reevoo.com</li>
<li>70.38.11.165             reviews.riverstreams.co.uk</li>
<li>70.38.11.165             reviews.techradar.com</li>
<li>70.38.11.165             av2010pro.com</li>
<li>70.38.11.165             review.deutsch.eazel.com</li>
<li>70.38.11.165             reviews.download.softwareload.de</li>
<li>70.38.11.165             r1.downloads.phpnuke.org</li>
<li>70.38.11.165             www.anti.actebis.com</li>
<li>70.38.11.165             www.antivirus-review.channelpartner.de</li>
<li>70.38.11.165             www.reviews.chip.de</li>
<li>70.38.11.165             www.dah5.ppks.net</li>
<li>70.38.11.165             www.test-reviews.softguide.de</li>
<li>70.38.11.165             www.review.virenschutz.ch</li>
<li>70.38.11.165             www.reviews.wave-computer.de</li>
<li>70.38.11.165             www.about.zdnet.de</li>
<li>70.38.11.165             www.soft-review.zdnet1.de</li>
<li>70.38.11.165             reviews.livix.blogspot.com</li>
<li>70.38.11.165             www.review-antivirus.alegsa.com.ar</li>
<li>70.38.11.165             www.ra1.analisis-antivirus.com</li>
<li>70.38.11.165             www.review.antivirusgratis.com.ar</li>
<li>70.38.11.165             www.soft-review.directoriowarez.com</li>
<li>70.38.11.165             www.arbest.grupogeek.com</li>
<li>70.38.11.165             www.best-reviews.pcasalvo.com</li>
<li>70.38.11.165             www.testing-av.pcdecasa.net</li>
<li>70.38.11.165             www.rz-x.wei.cl</li>
<li>70.38.11.165             www.review.yoreparo.com</li>
<li>70.38.11.165             reviews.coprocessing.be</li>
<li>70.38.11.165             lab.descary.com</li>
<li>70.38.11.165             review.fr.brothersoft.com</li>
<li>70.38.11.165             www.antilab-review.01net.com</li>
<li>70.38.11.165             www.review-lab.blogeek.ch</li>
<li>70.38.11.165             www.gr1.clubic.com</li>
<li>70.38.11.165             www.laboratory.commentcamarche.net</li>
<li>70.38.11.165             www.review.generation-nt.com</li>
<li>70.38.11.165             www.top-rev.host.fr</li>
<li>70.38.11.165             www.expert.infos-du-net.com</li>
<li>70.38.11.165             www.review.numerama.com</li>
<li>70.38.11.165             www.lab1-r.starzik.com</li>
<li>70.38.11.165             review-tests.italian.ircfast.com</li>
<li>70.38.11.165             www.labs.b2b24.ilsole24ore.com</li>
<li>70.38.11.165             www.ref1.blogslab.net</li>
<li>70.38.11.165             www.review.dvdprice.it</li>
<li>70.38.11.165             www.reviews.ebizitalia.it</li>
<li>70.38.11.165             www.review-software.hwgadget.com</li>
<li>70.38.11.165             www.exp-test.hwupgrade.it</li>
<li>70.38.11.165             www.full-reiew.lolasoft.it</li>
<li>70.38.11.165             www.dkl23.mondotechblog.com</li>
<li>70.38.11.165             www.antiviruses.sicurezzainrete.com</li>
<li>70.38.11.165             www.top.tomshw.it</li>
<li>70.38.11.165             avangate.com</li>
<li>70.38.11.165             regnow.com</li>
<li>70.38.11.165             shareit.com</li>
<li>70.38.11.165             eSellerate.net</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_1.png"><img class="alignnone size-medium wp-image-637" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_1-400x248.png" alt="" width="400" height="248" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_2.png"><img class="alignnone size-medium wp-image-638" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_2-400x67.png" alt="" width="400" height="67" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_3.png"><img class="alignnone size-medium wp-image-639" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_3-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_4.png"><img class="alignnone size-medium wp-image-640" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_4-400x301.png" alt="" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_5.png"><img class="alignnone size-medium wp-image-641" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_5-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_6.png"><img class="alignnone size-medium wp-image-642" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_6-400x400.png" alt="" width="400" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_7.png"><img class="alignnone size-medium wp-image-643" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_7-399x297.png" alt="" width="399" height="297" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_8.png"><img class="alignnone size-medium wp-image-644" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_8-400x289.png" alt="" width="400" height="289" /></a></p>
<p><strong>How to remove the infection of Fake Antivirus </strong><strong>(Adware.Win32.FakeAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a>. Run a full scan on all drives and move all detected      items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Soft Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 17:14:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntivirusSoft]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=627</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak   of the Antivirus Soft adware. a-squared   Anti-Malware detects this malware as Adware.Win32.AntivirusSoft.
Antivirus Soft is a rogue security program, come from hxxp:// newsoftspot.com. A rogue  application  tries to trick you by displaying false positive/misleading  scan results  report, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak   of the Antivirus Soft adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared   Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSoft" target="_blank">Adware.Win32.AntivirusSoft</a>.</p>
<p>Antivirus Soft is a rogue security program, come from hxxp:// newsoftspot.com. A rogue  application  tries to trick you by displaying false positive/misleading  scan results  report, which says that your computer is infected with  viruses or  trojan, but you will not be able to delete them before you  purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%\%random%sftav.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\avsoft</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, %random%</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, %random%</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_1.png"><img class="alignnone size-full wp-image-628" title="Adware.Win32.AntivirusSoft" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_1.png" alt="" width="358" height="136" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_2.png"><img class="alignnone size-medium wp-image-629" title="Adware.Win32.AntivirusSoft" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_3.png"><img class="alignnone size-medium wp-image-630" title="Adware.Win32.AntivirusSoft" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_3-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_4.png"><img class="alignnone size-medium wp-image-631" title="Adware.Win32.AntivirusSoft" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_4-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_5.png"><img class="alignnone size-medium wp-image-632" title="Adware.Win32.AntivirusSoft" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.AntivirusSoft_5-400x300.png" alt="" width="400" height="300" /></a></p>
<p><strong>How to remove the infection of Antivirus Soft </strong><strong>(Adware.Win32.</strong><strong>AntivirusSoft</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared     Anti-Malware</a>. Run a full scan on all drives and move all detected     items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivir Solution Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SafePcAv Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 16:56:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SafePcAv]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=618</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak        of the SafePcAv adware. a-squared        Anti-Malware detects this malware as Adware.Win32.SafePcAv.
SafePcAv, come from hxxp://www.safepcav.com, is a rogue    security     program. This is a new [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak        of the SafePcAv adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared        Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafePcAv" target="_blank">Adware.Win32.SafePcAv</a>.</p>
<p>SafePcAv, come from hxxp://www.safepcav.com, is a rogue    security     program. This is a new variant from Winiguard/Winisoft   family.  The     author of GuardWWW also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">GuardWWW</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>,&#8230; etc. To further convince victims SafePcAv, will also create numerous junk files with random names on       your  computer that will be detected as malware when the program  scans      your  computer, but will not allow you to remove them until  you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\always_delete.xml</li>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\always_skip.xml</li>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\main_config.xml</li>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\SafePcAv.exe</li>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\uninstall.exe</li>
<li>%ProgramFiles%\SafePcAv Software\SafePcAv\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\SafePcAv.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SafePcAv\1 SafePcAv.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SafePcAv\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SafePcAv\3 Uninstall.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SafePcAv</li>
<li>HKEY_LOCAL_MACHINE\software\SafePcAv</li>
<li>HKEY_CURRENT_USER\software\SafePcAv</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SafePcAv&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SafePcAv&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_1.png"><img class="alignnone size-medium wp-image-619" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_2.png"><img class="alignnone size-medium wp-image-620" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_3.png"><img class="alignnone size-medium wp-image-621" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_4.png"><img class="alignnone size-medium wp-image-622" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_5.png"><img class="alignnone size-medium wp-image-623" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_5-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_6.png"><img class="alignnone size-medium wp-image-624" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_6-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_7.png"><img class="alignnone size-medium wp-image-625" title="Adware.Win32.SafePcAv" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.SafePcAv_7-400x273.png" alt="" width="400" height="273" /></a></p>
<p><strong>How to remove the infection of SafePcAv </strong><strong>(Adware.Win32.</strong><strong>SafePcAv</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared    Anti-Malware</a>. Run a full scan on all drives and move all detected    items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemIron Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GuardWWW Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 17:05:38 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[GuardWWW]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=605</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak       of the GuardWWW adware. a-squared       Anti-Malware detects this malware as Adware.Win32.GuardWWW.
GuardWWW, come from hxxp://www.guardwww.com, is a rogue    security    program. This is a new variant from Winiguard/Winisoft [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak       of the GuardWWW adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared       Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">Adware.Win32.GuardWWW</a>.</p>
<p>GuardWWW, come from hxxp://www.guardwww.com, is a rogue    security    program. This is a new variant from Winiguard/Winisoft   family.  The    author of GuardWWW also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, etc. To further convince victims GuardWWW, will also create numerous junk files with random names on      your  computer that will be detected as malware when the program  scans     your  computer, but will not allow you to remove them until  you   purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\always_delete.xml</li>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\always_skip.xml</li>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\GuardWWW.exe</li>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\main_config.xml</li>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\uninstall.exe</li>
<li>%ProgramFiles%\GuardWWW Software\GuardWWW\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\GuardWWW.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardWWW\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardWWW\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardWWW\1 GuardWWW.lnk</li>
<li>%UserProfile%\Cookies\userdemo@guardwww[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\GuardWWW</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\GuardWWW</li>
<li>HKEY_CURRENT_USER\software\GuardWWW</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;GuardWWW&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;GuardWWW&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_1.png"><img class="alignnone size-medium wp-image-606" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_2.png"><img class="alignnone size-full wp-image-607" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_3.png"><img class="alignnone size-medium wp-image-608" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_4.png"><img class="alignnone size-medium wp-image-609" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_5.png"><img class="alignnone size-medium wp-image-610" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_6.png"><img class="alignnone size-medium wp-image-611" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_7.png"><img class="alignnone size-medium wp-image-612" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_8.png"><img class="alignnone size-medium wp-image-613" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_9.png"><img class="alignnone size-medium wp-image-614" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_10.png"><img class="alignnone size-medium wp-image-615" title="Adware.Win32.GuardWWW" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.GuardWWW_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><strong>How to remove the infection of GuardWWW </strong><strong>(Adware.Win32.</strong><strong>GuardWWW</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared   Anti-Malware</a>. Run a full scan on all drives and move all detected   items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemIron Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MyPcSecure Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 18:26:34 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[MyPcSecure]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=591</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak      of the MyPcSecure adware. a-squared      Anti-Malware detects this malware as Adware.Win32.MyPcSecure.
MyPcSecure, come from hxxp://www.mypcsecure.com, is a rogue   security    program. This is a new variant from Winiguard/Winisoft  family.  [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak      of the MyPcSecure adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">Adware.Win32.MyPcSecure</a>.</p>
<p>MyPcSecure, come from hxxp://www.mypcsecure.com, is a rogue   security    program. This is a new variant from Winiguard/Winisoft  family.  The    author of MyPcSecure also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, etc. To further convince victims MyPcSecure,  will also create numerous junk files with random names on     your  computer that will be detected as malware when the program scans     your  computer, but will not allow you to remove them until you   purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\always_delete.xml</li>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\always_skip.xml</li>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\main_config.xml</li>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\MyPcSecure.exe</li>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\uninstall.exe</li>
<li>%ProgramFiles%\MyPcSecure Software\MyPcSecure\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\MyPcSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\MyPcSecure\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\MyPcSecure\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\MyPcSecure\1 MyPcSecure.lnk</li>
<li>%UserProfile%\Cookies\userdemo@mypcsecure[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\MyPcSecure</li>
<li>HKEY_LOCAL_MACHINE\software\MyPcSecure</li>
<li>HKEY_CURRENT_USER\software\MyPcSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;MyPcSecure&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;MyPcSecure&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_1.png"><img class="alignnone size-medium wp-image-592" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_2.png"><img class="alignnone size-full wp-image-593" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_3.png"><img class="alignnone size-medium wp-image-594" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_4.png"><img class="alignnone size-medium wp-image-595" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_5.png"><img class="alignnone size-medium wp-image-596" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_6.png"><img class="alignnone size-medium wp-image-597" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_7.png"><img class="alignnone size-medium wp-image-598" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_8.png"><img class="alignnone size-medium wp-image-599" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_9.png"><img class="alignnone size-medium wp-image-600" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_10.png"><img class="alignnone size-medium wp-image-601" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_11.png"><img class="alignnone size-medium wp-image-602" title="Adware.Win32.MyPcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.MyPcSecure_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of MyPcSecure </strong><strong>(Adware.Win32.</strong><strong>MyPcSecure</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a>. Run a full scan on all drives and move all detected  items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemIron Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Total PC Defender 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 18:07:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Total PC Defender 2010]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=586</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak  of the Total PC Defender 2010 adware. a-squared  Anti-Malware detects this malware as Adware.Win32.TotalPCDefender2010.
Total PC Defender 2010 is a rogue security program. A rogue application  tries to trick you by displaying false positive/misleading scan results  report, which says that your [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak  of the Total PC Defender 2010 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalPCDefender2010" target="_blank">Adware.Win32.TotalPCDefender2010</a>.</p>
<p>Total PC Defender 2010 is a rogue security program. A rogue application  tries to trick you by displaying false positive/misleading scan results  report, which says that your computer is infected with viruses or  trojan, but you will not be able to delete them before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Total PC Defender\Total PC Defender.exe</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Total PC Defender.lnk</li>
<li>%UserProfile%\Desktop\Total PC Defender.lnk</li>
<li>%UserProfile%\Start Menu\Total PC Defender\Total PC Defender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Total PC Defender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Total PC Defender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.TotalPCDefender2010_1.png"><img class="alignnone size-medium wp-image-588" title="Adware.Win32.TotalPCDefender2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.TotalPCDefender2010_1-400x89.png" alt="" width="400" height="89" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.TotalPCDefender2010_2.png"><img class="alignnone size-medium wp-image-587" title="Adware.Win32.TotalPCDefender2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.TotalPCDefender2010_2-400x318.png" alt="" width="400" height="318" /></a></p>
<p><strong>How to remove the infection of Total PC Defender 2010 </strong><strong>(Adware.Win32.</strong><strong>TotalPCDefender2010</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a>. Run a full scan on all drives and move all detected  items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Advanced Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/26/windows-system-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows System Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/14/windows-enterprise-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Enterprise Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Defender 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PcSecureNet Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 14:06:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PcSecureNet]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=572</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak     of the PcSecureNet adware. a-squared     Anti-Malware detects this malware as Adware.Win32.PcSecureNet.
PcSecureNet, come from hxxp://www.pcsecurenet.com, is a rogue  security    program. This is a new variant from Winiguard/Winisoft family.  The    [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak     of the PcSecureNet adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared     Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">Adware.Win32.PcSecureNet</a>.</p>
<p>PcSecureNet, come from hxxp://www.pcsecurenet.com, is a rogue  security    program. This is a new variant from Winiguard/Winisoft family.  The    author of PcSecureNet also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>,     <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>,     <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims,  PcSecureNet will also create numerous junk files with random names on    your  computer that will be detected as malware when the program scans    your  computer, but will not allow you to remove them until you  purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\PcSecureNet Software\PcSecureNet\main_config.xml</li>
<li>%ProgramFiles%\PcSecureNet Software\PcSecureNet\PcSecureNet.exe</li>
<li>%ProgramFiles%\PcSecureNet Software\PcSecureNet\uninstall.exe</li>
<li>%SystemRoot%\System32\p6hxvcb5.exe</li>
<li>%SystemRoot%\System32\spool\PRTPROCS\W32X86\000012da.tmp</li>
<li>%SystemRoot%\System32\spool\PRTPROCS\W32X86\0000793d.tmp</li>
<li>%AllUsersProfile%\Desktop\PcSecureNet.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcSecureNet\1 PcSecureNet.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcSecureNet\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcSecureNet\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@pcsecurenet[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\0000216e</li>
<li>%UserProfile%\Local Settings\Temp\p6hxvcb5.exe</li>
<li>%UserProfile%\Local Settings\Temp\z6oi395v.exe</li>
<li>%UserProfile%\Local Settings\Temp\00002e31</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\PcSecureNet</li>
<li>HKEY_LOCAL_MACHINE\software\PcSecureNet</li>
<li>HKEY_CURRENT_USER\software\PcSecureNet</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;PcSecureNet&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;PcSecureNet&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_1.png"><img class="alignnone size-medium wp-image-573" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_2.png"><img class="alignnone size-medium wp-image-574" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_2-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_3.png"><img class="alignnone size-full wp-image-575" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_3.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_4.png"><img class="alignnone size-medium wp-image-576" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_4-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_5.png"><img class="alignnone size-medium wp-image-577" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_6.png"><img class="alignnone size-medium wp-image-578" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_7.png"><img class="alignnone size-medium wp-image-579" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_8.png"><img class="alignnone size-medium wp-image-580" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_8-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_9.png"><img class="alignnone size-medium wp-image-581" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_10.png"><img class="alignnone size-medium wp-image-582" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_11.png"><img class="alignnone size-medium wp-image-583" title="Adware.Win32.PcSecureNet" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcSecureNet_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of PcSecureNet </strong><strong>(Adware.Win32.</strong><strong>PcSecureNet</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared     Anti-Malware</a>. Run a full scan on all drives and move all detected     items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PcsSecure Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 15:13:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PcsSecure]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=557</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak    of the PcsSecure adware. a-squared    Anti-Malware detects this malware as Adware.Win32.PcsSecure.
PcsSecure, come from hxxp://www.pcssecure.com, is a rogue  security   program. This is a new variant from Winiguard/Winisoft family.  The   author of PcsSecure also [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak    of the PcsSecure adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared    Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">Adware.Win32.PcsSecure</a>.</p>
<p>PcsSecure, come from hxxp://www.pcssecure.com, is a rogue  security   program. This is a new variant from Winiguard/Winisoft family.  The   author of PcsSecure also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>,    <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>,    <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, PcsSecure will also create numerous junk files with random names on   your  computer that will be detected as malware when the program scans   your  computer, but will not allow you to remove them until you purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\always_delete.xml</li>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\always_skip.xml</li>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\main_config.xml</li>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\PcsSecure.exe</li>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\uninstall.exe</li>
<li>%ProgramFiles%\PcsSecure Software\PcsSecure\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\PcsSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsSecure\1 PcsSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsSecure\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsSecure\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@pcssecure[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\PcsSecure</li>
<li>HKEY_LOCAL_MACHINE\software\PcsSecure</li>
<li>HKEY_CURRENT_USER\software\PcsSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;PcsSecure&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;PcsSecure&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_1.png"><img class="alignnone size-medium wp-image-558" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_2.png"><img class="alignnone size-full wp-image-559" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_3.png"><img class="alignnone size-medium wp-image-560" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_4.png"><img class="alignnone size-medium wp-image-561" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_5.png"><img class="alignnone size-medium wp-image-562" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_6.png"><img class="alignnone size-medium wp-image-563" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_7.png"><img class="alignnone size-medium wp-image-564" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_8.png"><img class="alignnone size-medium wp-image-565" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_9.png"><img class="alignnone size-medium wp-image-566" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_10.png"><img class="alignnone size-medium wp-image-567" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_11.png"><img class="alignnone size-medium wp-image-568" title="Adware.Win32.PcsSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsSecure_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of PcsSecure </strong><strong>(Adware.Win32.</strong><strong>PcsSecure</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared    Anti-Malware</a>. Run a full scan on all drives and move all detected    items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/" rel="bookmark" class="crp_title">PcSecureNet Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APcSafe Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 15:00:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[APcSafe]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=544</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak   of the APcSafe adware. a-squared   Anti-Malware detects this malware as Adware.Win32.APcSafe.
APcSafe, come from hxxp://www.apcsafe.com, is a rogue  security  program. This is a new variant from Winiguard/Winisoft family.  The  author of APcSafe also made APcSecure, ProtectSoldier, ProtectDefender, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak   of the APcSafe adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared   Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">Adware.Win32.APcSafe</a>.</p>
<p>APcSafe, come from hxxp://www.apcsafe.com, is a rogue  security  program. This is a new variant from Winiguard/Winisoft family.  The  author of APcSafe also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>,   <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>,   <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims,  APcSafe will also create numerous junk files with random names on   your computer that will be detected as malware when the program scans   your computer, but will not allow you to remove them until you purchase   it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\APcSafe Software\APcSafe\always_skip.xml</li>
<li>%ProgramFiles%\APcSafe Software\APcSafe\APcSafe.exe</li>
<li>%ProgramFiles%\APcSafe Software\APcSafe\main_config.xml</li>
<li>%ProgramFiles%\APcSafe Software\APcSafe\uninstall.exe</li>
<li>%ProgramFiles%\APcSafe Software\APcSafe\always_delete.xml</li>
<li>%ProgramFiles%\APcSafe Software\APcSafe\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\APcSafe.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSafe\1 APcSafe.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSafe\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSafe\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@apcsafe[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\APcSafe</li>
<li>HKEY_CURRENT_USER\software\APcSafe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;APcSafe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;APcSafe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_1.png"><img class="alignnone size-medium wp-image-545" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_2.png"><img class="alignnone size-full wp-image-546" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_3.png"><img class="alignnone size-medium wp-image-547" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_4.png"><img class="alignnone size-medium wp-image-548" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_5.png"><img class="alignnone size-medium wp-image-549" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_6.png"><img class="alignnone size-medium wp-image-550" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_7.png"><img class="alignnone size-medium wp-image-551" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_8.png"><img class="alignnone size-medium wp-image-552" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_9.png"><img class="alignnone size-medium wp-image-553" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_10.png"><img class="alignnone size-medium wp-image-554" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_11.png"><img class="alignnone size-medium wp-image-555" title="Adware.Win32.APcSafe" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSafe_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of APcSafe </strong><strong>(Adware.Win32.</strong><strong>APcSafe</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared   Anti-Malware</a>. Run a full scan on all drives and move all detected   items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/" rel="bookmark" class="crp_title">PcSecureNet Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APcSecure Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 20:27:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[APcSecure]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=533</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak  of the APcSecure adware. a-squared  Anti-Malware detects this malware as Adware.Win32.APcSecure.
APcSecure, come from hxxp://www.apcsecure.com, is a rogue  security program. This is a new variant from Winiguard/Winisoft family.  The author of APcSecure also made ProtectSoldier, ProtectDefender, ArmorDefender, DefendAPc, SysDefenders, InSysSecure, SysProtector, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak  of the APcSecure adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">Adware.Win32.APcSecure</a>.</p>
<p>APcSecure, come from hxxp://www.apcsecure.com, is a rogue  security program. This is a new variant from Winiguard/Winisoft family.  The author of APcSecure also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, APcSecure will also create numerous junk files with random names on  your computer that will be detected as malware when the program scans  your computer, but will not allow you to remove them until you purchase  it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\APcSecure Software\APcSecure\APcSecure.exe</li>
<li>%ProgramFiles%\APcSecure Software\APcSecure\main_config.xml</li>
<li>%ProgramFiles%\APcSecure Software\APcSecure\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\APcSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSecure\1 APcSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSecure\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcSecure\3 Uninstall.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\APcSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\APcSecure</li>
<li>HKEY_CURRENT_USER\software\APcSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;APcSecure&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;APcSecure&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_1.png"><img class="alignnone size-medium wp-image-534" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_2.png"><img class="alignnone size-medium wp-image-535" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_3.png"><img class="alignnone size-medium wp-image-536" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_4.png"><img class="alignnone size-medium wp-image-537" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_5.png"><img class="alignnone size-medium wp-image-538" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_5-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_6.png"><img class="alignnone size-medium wp-image-539" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_6-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_7.png"><img class="alignnone size-medium wp-image-540" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_7-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_8.png"><img class="alignnone size-full wp-image-541" title="Adware.Win32.APcSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcSecure_8.png" alt="" width="330" height="216" /></a></p>
<p><strong>How to remove the infection of APcSecure </strong><strong>(Adware.Win32.APcSecure</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared  Anti-Malware</a>. Run a full scan on all drives and move all detected  items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/" rel="bookmark" class="crp_title">PcSecureNet Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ProtectSoldier Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 21:07:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ProtectSoldier]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=523</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the ProtectSoldier adware. a-squared Anti-Malware detects this malware as Adware.Win32.ProtectSoldier.
ProtectSoldier, come from hxxp://www.protectsoldier.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ProtectSoldier also made ProtectDefender, ArmorDefender, DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the ProtectSoldier adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">Adware.Win32.ProtectSoldier</a>.</p>
<p>ProtectSoldier, come from hxxp://www.protectsoldier.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ProtectSoldier also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, ProtectSoldier will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\ProtectSoldier Software\ProtectSoldier\always_delete.xml</li>
<li>%ProgramFiles%\ProtectSoldier Software\ProtectSoldier\always_skip.xml</li>
<li>%ProgramFiles%\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe</li>
<li>%ProgramFiles%\ProtectSoldier Software\ProtectSoldier\Uninstall.exe</li>
<li>%ProgramFiles%\ProtectSoldier Software\ProtectSoldier\quarantine\quarantine.xml</li>
<li>%UserProfile%\Cookies\userdemo@protectsoldier[2].txt</li>
<li>%UserProfile%\Desktop\ProtectSoldier.lnk</li>
<li>%UserProfile%\Start Menu\Programs\ProtectSoldier.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ProtectSoldier</li>
<li>HKEY_LOCAL_MACHINE\software\ProtectSoldier</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\agents</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\general</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\realtime</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\scanner</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\tasks</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\tasks\0</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\tasks\1</li>
<li>HKEY_CURRENT_USER\software\ProtectSoldier\updates</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;ProtectSoldier&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ProtectSoldier&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_1.png"><img class="alignnone size-medium wp-image-524" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_2.png"><img class="alignnone size-medium wp-image-525" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_3.png"><img class="alignnone size-medium wp-image-526" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_4.png"><img class="alignnone size-medium wp-image-527" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_5.png"><img class="alignnone size-medium wp-image-528" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_5-400x239.png" alt="" width="400" height="239" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_6.png"><img class="alignnone size-medium wp-image-529" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_6-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_7.png"><img class="alignnone size-medium wp-image-530" title="Adware.Win32.ProtectSoldier" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectSoldier_7-400x294.png" alt="" width="400" height="294" /></a></p>
<p><strong>How to remove the infection of </strong><strong>Protect</strong><strong>Soldier</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>Protect</strong><strong>Soldier</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/28/pcsecurenet-adware-removal-instructions/" rel="bookmark" class="crp_title">PcSecureNet Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ProtectDefender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/20/protectdefender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/20/protectdefender-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 22:33:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ProtectDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=509</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the ProtectDefender adware. a-squared Anti-Malware detects this malware as Adware.Win32.ProtectDefender.
ProtectDefender, come from hxxp://www.protectdefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ProtectDefender also made ArmorDefender, DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, ProtectPcs, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the ProtectDefender adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">Adware.Win32.ProtectDefender</a>.</p>
<p>ProtectDefender, come from hxxp://www.protectdefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ProtectDefender also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, ProtectDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\ProtectDefender Software\ProtectDefender\always_skip.xml</li>
<li>%ProgramFiles%\ProtectDefender Software\ProtectDefender\ProtectDefender.exe</li>
<li>%ProgramFiles%\ProtectDefender Software\ProtectDefender\Uninstall.exe</li>
<li>%ProgramFiles%\ProtectDefender Software\ProtectDefender\always_delete.xml</li>
<li>%ProgramFiles%\ProtectDefender Software\ProtectDefender\quarantine\quarantine.xml</li>
<li>%UserProfile%\Cookies\userdemo@protectdefender[2].txt</li>
<li>%UserProfile%\Desktop\ProtectDefender.lnk</li>
<li>%UserProfile%\Start Menu\Programs\ProtectDefender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\ProtectDefender</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\agents</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\general</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\realtime</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\scanner</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\tasks</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\tasks\0</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\tasks\1</li>
<li>HKEY_CURRENT_USER\software\ProtectDefender\updates</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ProtectDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;ProtectDefender&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ProtectDefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_1.png"><img class="alignnone size-medium wp-image-510" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_2.png"><img class="alignnone size-full wp-image-511" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_3.png"><img class="alignnone size-medium wp-image-512" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_3-400x234.png" alt="" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_4.png"><img class="alignnone size-medium wp-image-513" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_5.png"><img class="alignnone size-medium wp-image-514" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_6.png"><img class="alignnone size-medium wp-image-515" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_7.png"><img class="alignnone size-medium wp-image-516" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_8.png"><img class="alignnone size-medium wp-image-517" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_8-400x239.png" alt="" width="400" height="239" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_9.png"><img class="alignnone size-medium wp-image-518" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_9-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_10.png"><img class="alignnone size-medium wp-image-519" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_10-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_11.png"><img class="alignnone size-medium wp-image-520" title="Adware.Win32.ProtectDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ProtectDefender_11-400x285.png" alt="" width="400" height="285" /></a></p>
<p><strong>How to remove the infection of Protect</strong><strong>Defender</strong><strong> </strong><strong>(Adware.Win32.</strong><strong>Protect</strong><strong>Defender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectSoldier Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/20/protectdefender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ArmorDefender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/19/armordefender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/19/armordefender-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 20:58:17 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ArmorDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=493</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the ArmorDefender adware. a-squared Anti-Malware detects this malware as Adware.Win32.ArmorDefender.
ArmorDefender, come from hxxp://www.armordefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family, with a new GUI. The author of ArmorDefender also made DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the ArmorDefender adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">Adware.Win32.ArmorDefender</a>.</p>
<p>ArmorDefender, come from hxxp://www.armordefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family, with a new GUI. The author of ArmorDefender also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, ArmorDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\ArmorDefender Software\ArmorDefender\Uninstall.exe</li>
<li>%ProgramFiles%\ArmorDefender Software\ArmorDefender\ArmorDefender.exe</li>
<li>%SystemRoot%\system32\kus4.tmp.exe</li>
<li>%UserProfile%\Cookies\userdemo@armordefender[1].txt</li>
<li>%UserProfile%\Desktop\ArmorDefender.lnk</li>
<li>%UserProfile%\Local Settings\Temp\vow3.tmp.exe</li>
<li>%UserProfile%\Local Settings\Temp\kus4.tmp.exe</li>
<li>%UserProfile%\Start Menu\Programs\ArmorDefender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\ArmorDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ArmorDefender</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\agents</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\general</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\realtime</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\scanner</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\tasks</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\tasks\0</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\tasks\1</li>
<li>HKEY_CURRENT_USER\software\ArmorDefender\updates</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;ArmorDefender&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ArmorDefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_1.png"><img class="alignnone size-medium wp-image-494" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_1-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_2.png"><img class="alignnone size-medium wp-image-495" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_2-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_3.png"><img class="alignnone size-full wp-image-496" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_3.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_4.png"><img class="alignnone size-medium wp-image-497" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_4-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_5.png"><img class="alignnone size-medium wp-image-498" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_6.png"><img class="alignnone size-medium wp-image-499" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_7.png"><img class="alignnone size-medium wp-image-500" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_8.png"><img class="alignnone size-medium wp-image-501" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_8-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_9.png"><img class="alignnone size-medium wp-image-502" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_9-400x239.png" alt="" width="400" height="239" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_10.png"><img class="alignnone size-medium wp-image-503" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_10-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_11.png"><img class="alignnone size-medium wp-image-504" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_11-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_12.png"><img class="alignnone size-medium wp-image-505" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_12-400x222.png" alt="" width="400" height="222" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_13.png"><img class="alignnone size-medium wp-image-506" title="Adware.Win32.ArmorDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.ArmorDefender_13-400x285.png" alt="" width="400" height="285" /></a></p>
<p><strong>How to remove the infection of </strong><strong>ArmorDefender</strong><strong> </strong><strong>(Adware.Win32.ArmorDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/20/protectdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectSoldier Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/19/armordefender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win Security 360 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/18/win-security-360-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/18/win-security-360-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 20:55:43 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[WinSecurity360]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=487</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Win Security 360 adware. a-squared Anti-Malware detects this malware as Adware.Win32.WinSecurity360.
Win Security 360 is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Win Security 360 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinSecurity360" target="_blank">Adware.Win32.WinSecurity360</a>.</p>
<p>Win Security 360 is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\WinSecurity360\Win Security 360.url</li>
<li>%ProgramFiles%\WinSecurity360\Win Security 360 Help.url</li>
<li>%ProgramFiles%\WinSecurity360\WinSecurity360.exe</li>
<li>%ProgramFiles%\WinSecurity360\sk.lst</li>
<li>%UserProfile%\Application Data\WinSecurity360\vlc.dat</li>
<li>%UserProfile%\Application Data\WinSecurity360\WinSecurity360.ini</li>
<li>%UserProfile%\Application Data\WinSecurity360\rmd.dat</li>
<li>%UserProfile%\Desktop\Win Security 360.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Startup\Win Security 360.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Win Security 360\Website.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Win Security 360\Win Security 360.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Win Security 360\Win Security 360 Help.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\App Paths\WinSecurity360</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_1.png"><img class="alignnone size-medium wp-image-488" title="Adware.Win32.WinSecurity360" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_2.png"><img class="alignnone size-medium wp-image-489" title="Adware.Win32.WinSecurity360" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_2-400x245.png" alt="" width="400" height="245" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_3.png"><img class="alignnone size-medium wp-image-490" title="Adware.Win32.WinSecurity360" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.WinSecurity360_3-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of Win Security 360 </strong><strong>(Adware.Win32.</strong><strong>WinSecurity360</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Essentials 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/18/win-security-360-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DefendAPc Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 20:46:25 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[DefendAPc]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=474</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the DefendAPc adware. a-squared Anti-Malware detects this malware as Adware.Win32.DefendAPc.
DefendAPc, come from hxxp://www.defendapc.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of DefendAPc also made SysDefenders, InSysSecure, SysProtector, APcDefender, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the DefendAPc adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">Adware.Win32.DefendAPc</a>.</p>
<p>DefendAPc, come from hxxp://www.defendapc.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of DefendAPc also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, DefendAPc will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\always_delete.xml</li>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\always_skip.xml</li>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\DefendAPc.exe</li>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\main_config.xml</li>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\uninstall.exe</li>
<li>%ProgramFiles%\DefendAPc Software\DefendAPc\quarantine\quarantine.xml</li>
<li>%SystemRoot%\System32\spool\PRTPROCS\W32X86\00004e7f.tmp</li>
<li>%AllUsersProfile%\Desktop\DefendAPc.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\DefendAPc\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\DefendAPc\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\DefendAPc\1 DefendAPc.lnk</li>
<li>%UserProfile%\Cookies\userdemo@defendapc[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\DefendAPc</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\DefendAPc</li>
<li>HKEY_CURRENT_USER\software\DefendAPc</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;DefendAPc&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;DefendAPc&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_1.png"><img class="alignnone size-medium wp-image-475" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_2.png"><img class="alignnone size-full wp-image-476" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_3.png"><img class="alignnone size-medium wp-image-477" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_4.png"><img class="alignnone size-medium wp-image-478" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_5.png"><img class="alignnone size-medium wp-image-479" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_6.png"><img class="alignnone size-medium wp-image-480" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_7.png"><img class="alignnone size-medium wp-image-481" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_8.png"><img class="alignnone size-medium wp-image-482" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_9.png"><img class="alignnone size-medium wp-image-483" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_10.png"><img class="alignnone size-medium wp-image-484" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_11.png"><img class="alignnone size-medium wp-image-485" title="Adware.Win32.DefendAPc" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.DefendAPc_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of DefendAPc </strong><strong>(Adware.Win32.</strong><strong>DefendAPc</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/20/protectdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/21/protectsoldier-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectSoldier Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SysDefenders Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 20:03:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SysDefenders]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=460</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SysDefenders adware. a-squared Anti-Malware detects this malware as Adware.Win32.SysDefenders.
SysDefenders, come from hxxp://www.sysdefenders.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysDefenders also made InSysSecure, SysProtector, APcDefender, PcProtectar, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SysDefenders adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">Adware.Win32.SysDefenders</a>.</p>
<p>SysDefenders, come from hxxp://www.sysdefenders.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysDefenders also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SysDefenders will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\SysDefenders Software\SysDefenders\main_config.xml</li>
<li>%ProgramFiles%\SysDefenders Software\SysDefenders\SysDefenders.exe</li>
<li>%ProgramFiles%\SysDefenders Software\SysDefenders\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\SysDefenders.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysDefenders\1 SysDefenders.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysDefenders\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysDefenders\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@sysdefenders[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SysDefenders</li>
<li>HKEY_LOCAL_MACHINE\software\SysDefenders</li>
<li>HKEY_CURRENT_USER\software\SysDefenders</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SysDefenders&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SysDefenders&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_1.png"><img class="alignnone size-medium wp-image-461" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_2.png"><img class="alignnone size-full wp-image-462" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_3.png"><img class="alignnone size-medium wp-image-463" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_4.png"><img class="alignnone size-medium wp-image-464" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_5.png"><img class="alignnone size-medium wp-image-465" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_6.png"><img class="alignnone size-medium wp-image-466" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_7.png"><img class="alignnone size-medium wp-image-467" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_8.png"><img class="alignnone size-medium wp-image-468" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_9.png"><img class="alignnone size-medium wp-image-469" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_10.png"><img class="alignnone size-medium wp-image-470" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_11.png"><img class="alignnone size-medium wp-image-471" title="Adware.Win32.SysDefenders" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysDefenders_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of </strong><strong>SysDefenders</strong><strong> </strong><strong>(Adware.Win32.SysDefenders</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/" rel="bookmark" class="crp_title">DefendAPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/19/armordefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ArmorDefender Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InSysSecure Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 20:14:21 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[InSysSecure]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=447</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the InSysSecure adware. a-squared Anti-Malware detects this malware as Adware.Win32.InSysSecure.
InSysSecure, come from hxxp://www.insyssecure.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of InSysSecure also made SysProtector, APcDefender, PcProtectar, PcsProtector, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the InSysSecure adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">Adware.Win32.InSysSecure</a>.</p>
<p>InSysSecure, come from hxxp://www.insyssecure.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of InSysSecure also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, InSysSecure will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\InSysSecure Software\InSysSecure\InSysSecure.exe</li>
<li>%ProgramFiles%\InSysSecure Software\InSysSecure\main_config.xml</li>
<li>%ProgramFiles%\InSysSecure Software\InSysSecure\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\InSysSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\InSysSecure\1 InSysSecure.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\InSysSecure\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\InSysSecure\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@insyssecure[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\InSysSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\InSysSecure</li>
<li>HKEY_CURRENT_USER\software\InSysSecure</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;InSysSecure&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;InSysSecure&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_1.png"><img class="alignnone size-medium wp-image-448" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_2.png"><img class="alignnone size-full wp-image-449" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_3.png"><img class="alignnone size-medium wp-image-450" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_4.png"><img class="alignnone size-medium wp-image-451" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_5.png"><img class="alignnone size-medium wp-image-452" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_6.png"><img class="alignnone size-medium wp-image-453" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_7.png"><img class="alignnone size-medium wp-image-454" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_8.png"><img class="alignnone size-medium wp-image-455" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_8-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_9.png"><img class="alignnone size-medium wp-image-456" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_9-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_10.png"><img class="alignnone size-medium wp-image-457" title="Adware.Win32.InSysSecure" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.InSysSecure_10-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of InSysSecure </strong><strong>(Adware.Win32.</strong><strong>InSysSecure</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefenders Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/" rel="bookmark" class="crp_title">DefendAPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/pcssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guard Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 20:02:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Guard Pro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=442</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Guard Pro adware. a-squared Anti-Malware detects this malware as Adware.Win32.GuardPro.
GuardPro is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Guard Pro adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPro" target="_blank">Adware.Win32.GuardPro</a>.</p>
<p>GuardPro is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.</p>
<p><strong>Create new files and directories (some name of file/directory are random):</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\58969\VHf4c.exe</li>
<li>%AllUsersProfile%\Application Data\58969\VHOOK.ico</li>
<li>%AllUsersProfile%\Application Data\VHFEXIAPOOK\VHJRFXAOOK.cfg</li>
<li>%UserProfile%\Application Data\Guard Pro\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Guard Pro.lnk</li>
<li>%UserProfile%\Desktop\Guard Pro.lnk</li>
<li>%UserProfile%\Start Menu\Guard Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Guard Pro.lnk</li>
<li>%SystemRoot%\SYSTEM32\drivers\etc\hosts</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\trial_16f7c.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\trial_16f7c.DocHostUIHandler\Clsid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Guard Pro&#8221;</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_1.png"><img class="alignnone size-medium wp-image-443" title="Adware.Win32.GuardPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_1-400x291.png" alt="" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_2.png"><img class="alignnone size-medium wp-image-444" title="Adware.Win32.GuardPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_2-400x310.png" alt="" width="400" height="310" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_3.png"><img class="alignnone size-medium wp-image-445" title="Adware.Win32.GuardPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.GuardPro_3-400x286.png" alt="" width="400" height="286" /></a></p>
<p><strong>How to remove the infection of </strong><strong>GuardPro</strong><strong> </strong><strong>(Adware.Win32.GuardPro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/10/security-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SysProtector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 19:52:03 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SysProtector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=430</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SysProtector adware. a-squared Anti-Malware detects this malware as Adware.Win32.SysProtector.
SysProtector, come from hxxp://www.sysprotector.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysProtector also made APcDefender, PcProtectar, PcsProtector, GreatDefender, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SysProtector adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">Adware.Win32.SysProtector</a>.</p>
<p>SysProtector, come from hxxp://www.sysprotector.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysProtector also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SysProtector will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\SysProtector Software\SysProtector\SysProtector.exe</li>
<li>%ProgramFiles%\SysProtector Software\SysProtector\uninstall.exe</li>
<li>%ProgramFiles%\SysProtector Software\SysProtector\main_config.xml</li>
<li>%AllUsersProfile%\Desktop\SysProtector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysProtector\1 SysProtector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysProtector\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SysProtector\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@sysprotector[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SysProtector</li>
<li>HKEY_LOCAL_MACHINE\software\SysProtector</li>
<li>HKEY_CURRENT_USER\software\SysProtector</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SysProtector&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SysProtector&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_1.png"><img class="alignnone size-medium wp-image-431" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_2.png"><img class="alignnone size-full wp-image-432" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_3.png"><img class="alignnone size-medium wp-image-433" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_4.png"><img class="alignnone size-medium wp-image-434" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_5.png"><img class="alignnone size-medium wp-image-435" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_6.png"><img class="alignnone size-medium wp-image-436" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_7.png"><img class="alignnone size-medium wp-image-437" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_8.png"><img class="alignnone size-medium wp-image-438" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_8-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_9.png"><img class="alignnone size-medium wp-image-439" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_9-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_10.png"><img class="alignnone size-medium wp-image-440" title="Adware.Win32.SysProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.SysProtector_10-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of SysProtector </strong><strong>(Adware.Win32.</strong><strong>SysProtector</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefenders Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/" rel="bookmark" class="crp_title">DefendAPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/25/apcsafe-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSafe Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APcDefender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 19:54:16 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[APcDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=407</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the PcProtectar adware. a-squared Anti-Malware detects this malware as Adware.Win32.APcDefender.
APcDefender, come from hxxp://www.apcdefender.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of APcDefender also made PcProtectar, PcsProtector, GreatDefender, APCProtect, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the PcProtectar adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">Adware.Win32.APcDefender</a>.</p>
<p>APcDefender, come from hxxp://www.apcdefender.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of APcDefender also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, APcDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\APcDefender Software\APcDefender\APcDefender.exe</li>
<li>%ProgramFiles%\APcDefender Software\APcDefender\main_config.xml</li>
<li>%ProgramFiles%\APcDefender Software\APcDefender\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\APcDefender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcDefender\1 APcDefender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcDefender\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\APcDefender\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@apcdefender[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\APcDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\APcDefender</li>
<li>HKEY_CURRENT_USER\software\APcDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;APcDefender&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;APcDefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_1.png"><img class="alignnone size-medium wp-image-418" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_2.png"><img class="alignnone size-full wp-image-419" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_3.png"><img class="alignnone size-medium wp-image-420" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_3-400x314.png" alt="" width="400" height="314" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_4.png"><img class="alignnone size-medium wp-image-421" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_5.png"><img class="alignnone size-medium wp-image-422" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_6.png"><img class="alignnone size-medium wp-image-423" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_7.png"><img class="alignnone size-medium wp-image-424" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_8.png"><img class="alignnone size-medium wp-image-425" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_9.png"><img class="alignnone size-medium wp-image-426" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_10.png"><img class="alignnone size-medium wp-image-427" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_11.png"><img class="alignnone size-medium wp-image-428" title="Adware.Win32.APcDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.APcDefender_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of APcDefender </strong><strong>(Adware.Win32.</strong><strong>APcDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefenders Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/" rel="bookmark" class="crp_title">DefendAPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/22/apcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">APcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PcProtectar Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/06/pcprotectar-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/06/pcprotectar-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 18:45:38 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PcProtectar]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=394</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the PcProtectar adware. a-squared Anti-Malware detects this malware as Adware.Win32.PcProtectar.
PcProtectar, come from hxxp://www.pcprotectar.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of PcProtectar also made PcsProtector, GreatDefender, APCProtect, ProtectPcs, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the PcProtectar adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">Adware.Win32.PcProtectar</a>.</p>
<p>PcProtectar, come from hxxp://www.pcprotectar.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of PcProtectar also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, PcProtectar will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\PCprotectar Software\PCprotectar\PCprotectar.exe</li>
<li>%ProgramFiles%\PCprotectar Software\PCprotectar\uninstall.exe</li>
<li>%ProgramFiles%\PCprotectar Software\PCprotectar\main_config.xml</li>
<li>%AllUsersProfile%\Desktop\PCprotectar.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PCprotectar\1 PCprotectar.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PCprotectar\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PCprotectar\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@pcprotectar[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\PCprotectar</li>
<li>HKEY_LOCAL_MACHINE\software\PCprotectar</li>
<li>HKEY_CURRENT_USER\software\PCprotectar</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;PCprotectar&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;PCprotectar&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p>We have something different with this variant, there&#8217;s no English.</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_4.png"><img class="alignnone size-full wp-image-398" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_4.png" alt="" width="294" height="160" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_5.png"><img class="alignnone size-medium wp-image-399" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_6.png"><img class="alignnone size-medium wp-image-400" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_7.png"><img class="alignnone size-medium wp-image-401" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_8.png"><img class="alignnone size-medium wp-image-402" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_8-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_9.png"><img class="alignnone size-medium wp-image-403" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_10.png"><img class="alignnone size-medium wp-image-404" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_11.png"><img class="alignnone size-medium wp-image-405" title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_1.png"><img title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_2.png"><img title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_3.png"><img title="Adware.Win32.PCprotectar" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PCprotectar_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><strong>How to remove the infection of PcProtectar </strong><strong>(Adware.Win32.PcProtectar</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">APcDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefenders Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/18/defendapc-adware-removal-instructions/" rel="bookmark" class="crp_title">DefendAPc Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/06/pcprotectar-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NoMalware Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 15:44:49 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[NoMalware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=381</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the NoMalware adware. a-squared Anti-Malware detects this malware as Adware.Win32.NoMalware.
NoMalware is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the NoMalware adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.NoMalware" target="_blank">Adware.Win32.NoMalware</a>.</p>
<p>NoMalware is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.</p>
<p>NoMalware sites:</p>
<ul>
<li>hxxp:// nomalwares.org</li>
<li>hxxp:// nomalwarelab.com</li>
<li>hxxp:// malwaremechanic.com</li>
</ul>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_10.png"><img class="alignnone size-medium wp-image-382" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_10-400x306.png" alt="" width="400" height="306" /></a></p>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\NoMalware\NoMalware.exe</li>
<li> %ProgramFiles%\NoMalware\unins000.dat</li>
<li> %ProgramFiles%\NoMalware\unins000.exe</li>
<li> %ProgramFiles%\NoMalware\base.db</li>
<li> %AllUsersProfile%\Desktop\NoMalware.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\NoMalware\NoMalware.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\NoMalware\Uninstall NoMalware.lnk</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\NoMalware.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\NoMalware</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\{6268F50B-D811-4370-8483-C017BC9F0C9F}_is1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_1.png"><img class="alignnone size-medium wp-image-383" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_1-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="../wp-content/uploads/2010/01/Adware.Win32.NoMalware_2.png"><img title="Adware.Win32.NoMalware" src="../wp-content/uploads/2010/01/Adware.Win32.NoMalware_2-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_3.png"><img class="alignnone size-medium wp-image-385" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_3-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_4.png"><img class="alignnone size-medium wp-image-386" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_4-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_5.png"><img class="alignnone size-medium wp-image-387" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_5-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_6.png"><img class="alignnone size-medium wp-image-388" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_6-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_7.png"><img class="alignnone size-medium wp-image-389" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_7-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_8.png"><img class="alignnone size-medium wp-image-390" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_8-400x302.png" alt="" width="400" height="302" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_9.png"><img class="alignnone size-medium wp-image-391" title="Adware.Win32.NoMalware" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.NoMalware_9-400x302.png" alt="" width="400" height="302" /></a></p>
<p><strong>How to remove the infection of NoMalware </strong><strong>(Adware.Win32.</strong><strong>NoMalware</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/06/user-antivirus-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">User Antivirus 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/17/xp-micro-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Micro Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PcsProtector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 20:49:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PcsProtector]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=366</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the PcsProtector adware. a-squared Anti-Malware detects this malware as Adware.Win32.PcsProtector.
PcsProtector, come from hxxp://www.pcsprotector.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of PcsProtector also made GreatDefender, APCProtect, ProtectPcs, SysDefence, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the PcsProtector adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">Adware.Win32.PcsProtector</a>.</p>
<p>PcsProtector, come from hxxp://www.pcsprotector.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of PcsProtector also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">GreatDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, PcsProtector will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\PcsProtector Software\PcsProtector\PcsProtector.exe</li>
<li>%ProgramFiles%\PcsProtector Software\PcsProtector\uninstall.exe</li>
<li>%ProgramFiles%\PcsProtector Software\PcsProtector\main_config.xml</li>
<li>%AllUsersProfile%\Desktop\PcsProtector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsProtector\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsProtector\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PcsProtector\1 PcsProtector.lnk</li>
<li>%UserProfile%\Cookies\userdemo@pcsprotector[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\PcsProtector</li>
<li>HKEY_LOCAL_MACHINE\software\PcsProtector</li>
<li>HKEY_CURRENT_USER\software\PcsProtector</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;PcsProtector&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;PcsProtector&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_1.png"><img class="alignnone size-medium wp-image-367" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_2.png"><img class="alignnone size-full wp-image-368" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_3.png"><img class="alignnone size-medium wp-image-369" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_3-400x321.png" alt="" width="400" height="321" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_4.png"><img class="alignnone size-medium wp-image-370" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_5.png"><img class="alignnone size-medium wp-image-371" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_6.png"><img class="alignnone size-medium wp-image-372" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_7.png"><img class="alignnone size-medium wp-image-373" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_8.png"><img class="alignnone size-medium wp-image-374" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_9.png"><img class="alignnone size-medium wp-image-375" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_10.png"><img class="alignnone size-medium wp-image-376" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_11.png"><img class="alignnone size-medium wp-image-377" title="Adware.Win32.PcsProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/01/Adware.Win32.PcsProtector_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of PcsProtector </strong><strong>(Adware.Win32.</strong><strong>PcsProtector</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">APcDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/06/pcprotectar-adware-removal-instructions/" rel="bookmark" class="crp_title">PcProtectar Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/12/sysdefenders-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefenders Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpyEraser Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/30/spyeraser-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/30/spyeraser-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 19:10:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SpyEraser]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=292</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SpyEraser adware. a-squared Anti-Malware detects this malware as Adware.Win32.SpyEraser.
SpyEraser is a rogue scanner program. This fake scanner application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SpyEraser adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SpyEraser" target="_blank">Adware.Win32.SpyEraser</a>.</p>
<p>SpyEraser is a rogue scanner program. This fake scanner application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application.</p>
<p><strong>SpyEraser sites:</strong></p>
<ul>
<li>hxxp://www. spyeraser-security.com</li>
<li>hxxp://www. spyeraser-trial.com</li>
</ul>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\SpyEraser\data.dll</li>
<li>%ProgramFiles%\SpyEraser\SpyEraser.exe</li>
<li>%ProgramFiles%\SpyEraser\Uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\SpyEraser.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SpyEraser\SpyEraser\Launch SpyEraser.exe.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SpyEraser\SpyEraser\SpyEraser Uninstall.exe.lnk</li>
<li>%UserProfile%\Local Settings\Application Data\Downloaded Installations\{E5FF35CB-AAE1-4CD6-BFDE-D0BCE9CCBA4C}\SpyEraser.msi</li>
<li>%SystemRoot%\Installer\{6A2724E2-5E36-4F2E-9B3D-4A716774B3F9}\SpyEraser.exe1_5D3FA81F1A6D4924AD5250A57005F147.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\Features\2E4272A663E5E2F4B9D3A41776473B9F</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList\Media</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList\Net</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Installer\UpgradeCodes\21B289D0EDBF1BD48A4C39C60AF74DE9</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\SpyEraser</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\21B289D0EDBF1BD48A4C39C60AF74DE9</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA061871792C67E4997020ED0AF0253E</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBAB827A17F9D9B40B5A18854589281C</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Features</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\InstallProperties</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Patches</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Usage</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\{6A2724E2-5E36-4F2E-9B3D-4A716774B3F9}</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_6.png"><img class="alignnone size-full wp-image-293" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_6.png" alt="" width="317" height="353" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_7.png"><img class="alignnone size-medium wp-image-294" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_7-400x326.png" alt="" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_8.png"><img class="alignnone size-medium wp-image-295" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_8-400x326.png" alt="" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_9.png"><img class="alignnone size-medium wp-image-296" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_9-343x400.png" alt="" width="343" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_10.png"><img class="alignnone size-medium wp-image-297" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_10-400x257.png" alt="" width="400" height="257" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_11.png"><img class="alignnone size-medium wp-image-298" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_11-290x400.png" alt="" width="290" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_12.png"><img class="alignnone size-medium wp-image-299" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_12-400x326.png" alt="" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_13.png"><img class="alignnone size-medium wp-image-300" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_13-400x326.png" alt="" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_14.png"><img class="alignnone size-medium wp-image-301" title="Adware.Win32.SpyEraser" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SpyEraser_14-400x311.png" alt="" width="400" height="311" /></a></p>
<p><strong>How to remove the infection of SpyEraser </strong><strong>(Adware.Win32.</strong><strong>SpyEraser</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemCleanerPro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/30/spyeraser-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GreatDefender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 18:47:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[GreatDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=279</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the GreatDefender adware. a-squared Anti-Malware detects this malware as Adware.Win32.GreatDefender.
GreatDefender, come from hxxp://www.greatdefender.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of GreatDefender also made APCProtect, ProtectPcs, SysDefence, TheDefend, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the GreatDefender adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GreatDefender" target="_blank">Adware.Win32.GreatDefender</a>.</p>
<p>GreatDefender, come from hxxp://www.greatdefender.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of GreatDefender also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">APCProtect</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, GreatDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\GreatDefender Software\GreatDefender\GreatDefender.exe</li>
<li>%ProgramFiles%\GreatDefender Software\GreatDefender\main_config.xml</li>
<li>%ProgramFiles%\GreatDefender Software\GreatDefender\uninstall.exe</li>
<li>%AllUsersProfiles%\Desktop\GreatDefender.lnk</li>
<li>%AllUsersProfiles%\Start Menu\Programs\GreatDefender\2 Homepage.lnk</li>
<li>%AllUsersProfiles%\Start Menu\Programs\GreatDefender\3 Uninstall.lnk</li>
<li>%AllUsersProfiles%\Start Menu\Programs\GreatDefender\1 GreatDefender.lnk</li>
<li>%UserProfile%\Cookies\userdemo@greatdefender[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\GreatDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\GreatDefender</li>
<li>HKEY_CURRENT_USER\software\GreatDefender</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;GreatDefender&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;GreatDefender&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_1.png"><img class="alignnone size-medium wp-image-280" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_2.png"><img class="alignnone size-full wp-image-281" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_3.png"><img class="alignnone size-medium wp-image-282" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_4.png"><img class="alignnone size-medium wp-image-283" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_5.png"><img class="alignnone size-medium wp-image-284" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_6.png"><img class="alignnone size-medium wp-image-285" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_7.png"><img class="alignnone size-medium wp-image-286" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_8.png"><img class="alignnone size-medium wp-image-287" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_9.png"><img class="alignnone size-medium wp-image-288" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_10.png"><img class="alignnone size-medium wp-image-289" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_11.png"><img class="alignnone size-medium wp-image-290" title="Adware.Win32.GreatDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GreatDefender_11-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of GreatDefender </strong><strong>(Adware.Win32.</strong><strong>GreatDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">APcDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/06/pcprotectar-adware-removal-instructions/" rel="bookmark" class="crp_title">PcProtectar Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Antivirus PC 2009 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 18:16:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Antivirus PC 2009]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=271</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Antivirus PC 2009 adware. a-squared Anti-Malware detects this malware as Adware.Win32.AntivirusPC2009.
Antivirus PC 2009 is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Antivirus PC 2009 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusPC2009" target="_blank">Adware.Win32.AntivirusPC2009</a>.</p>
<p>Antivirus PC 2009 is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\Antivirus PC 2009\2.vbs</li>
<li>%ProgramFiles%\Antivirus PC 2009\avpc2009.exe</li>
<li>%ProgramFiles%\Antivirus PC 2009\avpc2009s.exe</li>
<li>%ProgramFiles%\Antivirus PC 2009\bzip2.dll</li>
<li>%ProgramFiles%\Antivirus PC 2009\libltdl3.dll</li>
<li>%ProgramFiles%\Antivirus PC 2009\pthreadVC2.dll</li>
<li>%ProgramFiles%\Antivirus PC 2009\Uninstaller.exe</li>
<li>%ProgramFiles%\Antivirus PC 2009\data\daily.cvd</li>
<li>%ProgramFiles%\Antivirus PC 2009\data\self.hdb</li>
<li>%ProgramFiles%\Antivirus PC 2009\data\</li>
<li>%ProgramFiles%\Antivirus PC 2009\quarantine\</li>
<li>%UserProfile%\Desktop\Antivirus PC 2009.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus PC 2009.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Antivirus PC 2009</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Antivirus PC 2009&#8243;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Antivirus PC 2009&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_1.png"><img class="alignnone size-medium wp-image-272" title="Adware.Win32.AntivirusPC2009" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_1-400x291.png" alt="" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_2.png"><img class="alignnone size-medium wp-image-273" title="Adware.Win32.AntivirusPC2009" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_2-400x291.png" alt="" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_3.png"><img class="alignnone size-medium wp-image-274" title="Adware.Win32.AntivirusPC2009" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_3-400x283.png" alt="" width="400" height="283" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_4.png"><img class="alignnone size-medium wp-image-275" title="Adware.Win32.AntivirusPC2009" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_4-400x269.png" alt="" width="400" height="269" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_5.png"><img class="alignnone size-medium wp-image-276" title="Adware.Win32.AntivirusPC2009" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntivirusPC2009_5-400x59.png" alt="" width="400" height="59" /></a></p>
<p><strong>How to remove the infection of Antivirus PC 2009 </strong><strong>(Adware.Win32.AntivirusPC2009</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/paladin-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Paladin Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemCleanerPro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Antispyware Shield Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 19:39:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Antispyware Shield Pro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=254</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Antispyware Shield Pro adware. a-squared Anti-Malware detects this malware as Adware.Win32.AntispywareShieldPro.
Antispyware Shield Pro is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Antispyware Shield Pro adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntispywareShieldPro" target="_blank">Adware.Win32.AntispywareShieldPro</a>.</p>
<p>Antispyware Shield Pro is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p>When installing, it try to make HTTP GET to the following url:</p>
<ul>
<li>hxxp://scanner.entiresafescripts.net/installation/</li>
</ul>
<p>The entiresafescripts.net itself will look like this:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_9.png"><img class="alignnone size-medium wp-image-263" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_9-400x326.png" alt="" width="400" height="326" /></a></p>
<p>Then you will be redirected to the fake scanner:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_10.png"><img class="alignnone size-medium wp-image-264" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_10-399x64.png" alt="" width="399" height="64" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_11.png"><img class="alignnone size-medium wp-image-265" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_11-400x221.png" alt="" width="400" height="221" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_12.png"><img class="alignnone size-medium wp-image-266" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_12-400x66.png" alt="" width="400" height="66" /></a></p>
<p>When running the application, you can see &#8220;Official web site&#8221; button on the top of the form, and if you click this button, it take you to hxxp://systemcleanerspro.net, and this site will offer you another rogue application, called &#8220;<a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" target="_blank">SystemCleanerPro</a>&#8220;, a-squared Anti-Malware know this as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCleanerPro" target="_blank">Adware.Win32.SystemCleanerPro</a>.</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_13.png"><img class="alignnone size-medium wp-image-267" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_13-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_14.png"><img class="alignnone size-medium wp-image-268" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_14-400x319.png" alt="" width="400" height="319" /></a></p>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\Antispyware Shield Pro\License.rtf</li>
<li>%ProgramFiles%\Antispyware Shield Pro\uninst.exe</li>
<li>%ProgramFiles%\Antispyware Shield Pro\antispyshield.exe</li>
<li>%UserProfile%\Desktop\Antispyware Shield Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antispyware Shield Pro\Antispyware Shield Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antispyware Shield Pro\Uninstall.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\App Paths\antispyshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Antispyware Shield Pro</li>
<li>HKEY_CURRENT_USER\software\Entire Safe Scripts Ltd</li>
<li>HKEY_CURRENT_USER\software\Entire Safe Scripts Ltd\Antispyware Shield Pro</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_1.png"><img class="alignnone size-medium wp-image-255" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_2.png"><img class="alignnone size-medium wp-image-256" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_3.png"><img class="alignnone size-medium wp-image-257" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_4.png"><img class="alignnone size-medium wp-image-258" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_5.png"><img class="alignnone size-medium wp-image-259" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_5-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_6.png"><img class="alignnone size-medium wp-image-260" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_6-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_7.png"><img class="alignnone size-medium wp-image-261" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_7-400x280.png" alt="" width="400" height="280" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_8.png"><img class="alignnone size-medium wp-image-262" title="Adware.Win32.AntispywareShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntispywareShieldPro_8-400x300.png" alt="" width="400" height="300" /></a></p>
<p><strong>How to remove the infection of Antispyware Shield Pro </strong><strong>(Adware.Win32.</strong><strong>AntispywareShieldPro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemCleanerPro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/30/spyeraser-adware-removal-instructions/" rel="bookmark" class="crp_title">SpyEraser Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SystemCleanerPro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 18:30:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SystemCleanerPro]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=244</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SystemCleanerPro adware. a-squared Anti-Malware detects this malware as Adware.Win32.SystemCleanerPro.
SystemCleanerPro is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SystemCleanerPro adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCleanerPro" target="_blank">Adware.Win32.SystemCleanerPro</a>.</p>
<p>SystemCleanerPro is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files and directories:</strong></p>
<ul>
<li>%ProgramFiles%\SystemCleanerPRO\sysclpro.exe</li>
<li>%ProgramFiles%\SystemCleanerPRO\unins000.dat</li>
<li>%ProgramFiles%\SystemCleanerPRO\unins000.exe</li>
<li>%ProgramFiles%\SystemCleanerPRO\killtask.bat</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemCleanerPRO\Uninstall SystemCleanerPRO.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemCleanerPRO\SystemCleanerPRO.lnk</li>
<li>%AllUsersProfile%\Application Data\AuxCo\</li>
<li>%AllUsersProfile%\Application Data\AuxCo\SystemCleanerPRO\</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SystemCleanerPRO_is1</li>
<li>HKEY_CURRENT_USER\software\AuxCo</li>
<li>HKEY_CURRENT_USER\software\AuxCo\SystemCleanerPRO</li>
<li>HKEY_CURRENT_USER\software\AuxCo\SystemCleanerPRO\2.2</li>
<li>HKEY_CURRENT_USER\software\AuxCo\SystemCleanerPRO\2.2\config</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SystemCleanerPRO&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_1.png"><img class="alignnone size-medium wp-image-245" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_1-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_2.png"><img class="alignnone size-medium wp-image-246" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_2-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_3.png"><img class="alignnone size-medium wp-image-247" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_3-400x311.png" alt="" width="400" height="311" /></a><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_4.png"></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_4.png"><img class="alignnone size-medium wp-image-248" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_4-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_5.png"><img class="alignnone size-medium wp-image-249" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_5-400x311.png" alt="" width="400" height="311" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_6.png"><img class="alignnone size-medium wp-image-250" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_6-400x400.png" alt="" width="400" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_7.png"><img class="alignnone size-medium wp-image-251" title="Adware.Win32.SystemCleanerPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemCleanerPro_7-400x272.png" alt="" width="400" height="272" /></a></p>
<p><strong>How to remove the infection of SystemCleanerPro </strong><strong>(Adware.Win32.</strong><strong>SystemCleanerPro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/05/nomalware-adware-removal-instructions/" rel="bookmark" class="crp_title">NoMalware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/11/smart-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APCProtect Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 18:49:36 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[apcprotect]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=227</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the APCProtect  adware. a-squared Anti-Malware detects this malware as Adware.Win32.APCProtect.
APCProtect, come from hxxp://www.apcprotect.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of APCProtect also made ProtectPcs, SysDefence, TheDefend, GuardPcs, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the APCProtect  adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APCProtect" target="_blank">Adware.Win32.APCProtect</a>.</p>
<p>APCProtect, come from hxxp://www.apcprotect.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of APCProtect also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">ProtectPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, APCProtect will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\APCProtect Software\APCProtect\APCProtect.exe</li>
<li> %ProgramFiles%\APCProtect Software\APCProtect\main_config.xml</li>
<li> %ProgramFiles%\APCProtect Software\APCProtect\uninstall.exe</li>
<li> %AllUsersProfile%\Desktop\APCProtect.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\APCProtect\2 Homepage.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\APCProtect\3 Uninstall.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\APCProtect\1 APCProtect.lnk</li>
<li>%UserProfile%\Cookies\userdemo@apcprotect[1].txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\APCProtect</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\APCProtect</li>
<li> HKEY_CURRENT_USER\software\APCProtect</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;APCProtect&#8221;</li>
<li> HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;APCProtect.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;APCProtect&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_1.png"><img class="alignnone size-medium wp-image-228" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_2.png"><img class="alignnone size-full wp-image-229" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_3.png"><img class="alignnone size-medium wp-image-230" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_4.png"><img class="alignnone size-full wp-image-231" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_4.png" alt="" width="280" height="296" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_5.png"><img class="alignnone size-medium wp-image-232" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_6.png"><img class="alignnone size-medium wp-image-233" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_7.png"><img class="alignnone size-medium wp-image-234" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_8.png"><img class="alignnone size-medium wp-image-235" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_8-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_9.png"><img class="alignnone size-medium wp-image-236" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_9-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_10.png"><img class="alignnone size-medium wp-image-237" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_10-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_11.png"><img class="alignnone size-medium wp-image-238" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_11-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_12.png"><img class="alignnone size-full wp-image-239" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_12.png" alt="" width="330" height="216" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_13.png"><img class="alignnone size-medium wp-image-240" title="Adware.Win32.APCProtect" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.APCProtect_13-400x295.png" alt="" width="400" height="295" /></a></p>
<p><strong>How to remove the infection of </strong><strong>APCProtect</strong><strong> </strong><strong>(Adware.Win32.APCProtect</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">GreatDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">APcDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/insyssecure-adware-removal-instructions/" rel="bookmark" class="crp_title">InSysSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ProtectPcs Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/21/protectpcs-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/21/protectpcs-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 17:22:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[protectpcs]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=214</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the ProtectPcs adware. a-squared Anti-Malware detects this malware as Adware.Win32.ProtectPcs.
ProtectPcs, come from hxxp://www.protectpcs.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of ProtectPcs also made SysDefence, TheDefend, GuardPcs, IGuardPc, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the ProtectPcs adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectPcs" target="_blank">Adware.Win32.ProtectPcs</a>.</p>
<p>ProtectPcs, come from hxxp://www.protectpcs.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of ProtectPcs also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">SysDefence</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, ProtectPcs will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\ProtectPcs Software\ProtectPcs\ProtectPcs.exe</li>
<li>%ProgramFiles%\ProtectPcs Software\ProtectPcs\uninstall.exe</li>
<li>%ProgramFiles%\ProtectPcs Software\ProtectPcs\main_config.xml</li>
<li>%AllUsersProfile%\Desktop\ProtectPcs.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\ProtectPcs\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\ProtectPcs\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\ProtectPcs\1 ProtectPcs.lnk</li>
<li>%UserProfile%\Cookies\userdemo@protectpcs.txt</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ProtectPcs</li>
<li>HKEY_LOCAL_MACHINE\software\ProtectPcs</li>
<li>HKEY_CURRENT_USER\software\ProtectPcs</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;ProtectPcs&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ProtectPcs.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;ProtectPcs&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_1.png"><img class="alignnone size-medium wp-image-215" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_1-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_2.png"><img class="alignnone size-full wp-image-216" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_2.png" alt="" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_3.png"><img class="alignnone size-medium wp-image-217" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_3-400x300.png" alt="" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_4.png"><img class="alignnone size-medium wp-image-218" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_5.png"><img class="alignnone size-medium wp-image-219" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_6.png"><img class="alignnone size-medium wp-image-220" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_7.png"><img class="alignnone size-medium wp-image-221" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_7-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_8.png"><img class="alignnone size-medium wp-image-222" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_8-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_9.png"><img class="alignnone size-medium wp-image-223" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_9-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_10.png"><img class="alignnone size-medium wp-image-224" title="Adware.Win32.ProtectPcs" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.ProtectPcs_10-400x273.png" alt="" width="400" height="273" /></a></p>
<p><strong>How to remove the infection of </strong><strong>ProtectPcs</strong><strong> </strong><strong>(Adware.Win32.ProtectPcs</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/" rel="bookmark" class="crp_title">APCProtect Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">GreatDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/07/apcdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">APcDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/21/protectpcs-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Defense Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 17:08:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=208</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Malware Defense adware. a-squared Anti-Malware detects this malware as Adware.Win32.MalwareDefense.
Malware Defense is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Malware Defense adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareDefense" target="_blank">Adware.Win32.MalwareDefense</a>.</p>
<p>Malware Defense is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Malware Defense\md.db</li>
<li>%ProgramFiles%\Malware Defense\mdefense.exe</li>
<li>%ProgramFiles%\Malware Defense\mdext.dll</li>
<li>%ProgramFiles%\Malware Defense\uninstall.exe</li>
<li>%ProgramFiles%\Malware Defense\help.ico</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Defense.lnk</li>
<li>%UserProfile%\Desktop\Malware Defense ReadMe.txt</li>
<li>%UserProfile%\Desktop\Malware Defense Support.lnk</li>
<li>%UserProfile%\Desktop\Malware Defense.lnk</li>
<li>%UserProfile%\Local Settings\Temp\av.dat</li>
<li>%UserProfile%\Local Settings\Temp\dv.dat</li>
<li>%UserProfile%\Local Settings\Temp\4otjesjty.mof</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Malware Defense Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Uninstall Malware Defense.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Malware Defense.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Malware Defense</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Malware Defense</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Malware Defense&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_1.png"><img class="alignnone size-medium wp-image-209" title="Adware.Win32.MalwareDefense" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_1-400x308.png" alt="" width="400" height="308" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_2.png"><img class="alignnone size-medium wp-image-210" title="Adware.Win32.MalwareDefense" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_2-400x308.png" alt="" width="400" height="308" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_4.png"><img class="alignnone size-medium wp-image-212" title="Adware.Win32.MalwareDefense" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_4-400x302.png" alt="" width="400" height="302" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_3.png"><img class="alignnone size-medium wp-image-211" title="Adware.Win32.MalwareDefense" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.MalwareDefense_3-400x228.png" alt="" width="400" height="228" /></a></p>
<p><strong>How to remove the infection of Malware Defense</strong><strong> </strong><strong>(Adware.Win32.MalwareDefense)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemCleanerPro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SysDefence Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/18/sysdefence-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/18/sysdefence-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 20:01:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SysDefence]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=111</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SysDefence adware. a-squared Anti-Malware detects this malware as Adware.Win32.SysDefence.
SysDefence, come from hxxp://www.sysdefence.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysDefence also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SysDefence adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefence" target="_blank">Adware.Win32.SysDefence</a>.</p>
<p>SysDefence, come from hxxp://www.sysdefence.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysDefence also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SysDefence will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SysDefence Software\SysDefence\SysDefence.exe</li>
<li> %ProgramFiles%\SysDefence Software\SysDefence\uninstall.exe</li>
<li> %ProgramFiles%\SysDefence Software\SysDefence\main_config.xml</li>
<li> %AllUsersProfile%\Desktop\SysDefence.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\SysDefence\1 SysDefence.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\SysDefence\2 Homepage.lnk</li>
<li> %AllUsersProfile%\Start Menu\Programs\SysDefence\3 Uninstall.lnk</li>
<li> %UserProfile%\Cookies\userdemo@sysdefence[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsq6.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SysDefence</li>
<li> HKEY_LOCAL_MACHINE\software\SysDefence</li>
<li> HKEY_CURRENT_USER\software\SysDefence</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SysDefence&#8221;</li>
<li> HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SysDefence.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SysDefence&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_1.png"><img class="alignnone size-medium wp-image-112" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_1-400x313.png" alt="Adware.Win32.SysDefence" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_2.png"><img class="alignnone size-full wp-image-113" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_2.png" alt="Adware.Win32.SysDefence_2" width="395" height="333" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_4.png"><img class="alignnone size-medium wp-image-114" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_4-400x300.png" alt="Adware.Win32.SysDefence" width="400" height="300" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_5.png"><img class="alignnone size-medium wp-image-115" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_5-400x312.png" alt="Adware.Win32.SysDefence" width="400" height="312" /></a><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_6.png"></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_6.png"><img class="alignnone size-medium wp-image-116" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_6-400x312.png" alt="Adware.Win32.SysDefence" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_7.png"><img class="alignnone size-medium wp-image-117" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_7-400x312.png" alt="Adware.Win32.SysDefence" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_8.png"><img class="alignnone size-medium wp-image-118" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_8-400x312.png" alt="Adware.Win32.SysDefence" width="400" height="312" /></a><a href="../wp-content/uploads/2009/12/Adware.Win32.SysDefence_11.png"></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_12.png"><img class="alignnone size-medium wp-image-122" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_12-400x295.png" alt="Adware.Win32.SysDefence" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_9.png"><img class="alignnone size-medium wp-image-119" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_9-400x273.png" alt="Adware.Win32.SysDefence" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_10.png"><img class="alignnone size-medium wp-image-120" title="Adware.Win32.SysDefence" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SysDefence_10-400x295.png" alt="Adware.Win32.SysDefence" width="400" height="295" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of SysDefence </span></strong><strong><span style="font-size: small;">(Adware.Win32.SysDefence</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/21/protectpcs-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectPcs Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/" rel="bookmark" class="crp_title">APCProtect Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">GreatDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsProtector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/sysprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">SysProtector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/18/sysdefence-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Adware Scanner 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/17/system-adware-scanner-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/17/system-adware-scanner-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 15:58:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Adware Scanner 2010]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=76</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the System Adware Scanner 2010 adware. a-squared Anti-Malware detects this malware as Adware.Win32.SystemAdwareScanner2010.
System Adware Scanner 2010, come from hxxp://sysadscanner.com, is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the System Adware Scanner 2010 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemAdwareScanner2010" target="_blank">Adware.Win32.SystemAdwareScanner2010</a>.</p>
<p>System Adware Scanner 2010, come from hxxp://sysadscanner.com, is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying fake warning messages and misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p>Their site also have a funny things. When we look at the System Adware Scanner 2010 Management Team (hxxp://sysadscanner.com/about.php), we can see this information:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team1.png"><img class="alignnone size-medium wp-image-77" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team1-400x268.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="268" /></a></p>
<p>This page tell us some people behind this product. Do not believe it, it&#8217;s fake! How do we know it&#8217;s fake? Let we do some search on Google from sentence that we found on that page. Example, we try to search <em>&#8220;Dale Fuller is a leading technology executive with extensive experience in starting up and growing both technology and consumer businesses&#8221;</em>. Then we got this results:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team3.png"><img class="alignnone size-medium wp-image-79" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team3-400x397.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="397" /></a></p>
<p>The first results is a page from AVG antivirus company. So, lets click it. Then,</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team21.png"><img class="alignnone size-medium wp-image-80" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Team21-400x291.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="291" /></a></p>
<p>Looks very similar <em>hah</em>? Now, you have proven that the System Adware Scanner 2010 Management Team is a fake!</p>
<p>Interested with this rogue, we decided to dig a little deeper, and loaded it into the debugger. Yep, this rogue is packed and encrypted. The run-time packer will rebuild a new unpacked PE file on the memory. Running this application on virtual environment will get no results, because it have some protection. And this is one of its protection, checking presence of VMware.</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_VMWare.png"><img class="alignnone size-medium wp-image-100" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_VMWare-400x155.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="155" /></a></p>
<p>This rogue also check the presence of anti-virus/anti-malware on the victim machine, then kill them. Here&#8217;s the list (left side are encrypted, and the right side are decrypted):</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_StringsAV.png"><img class="alignnone size-full wp-image-101" style="border: 1px solid black;" title="Adware.Win32.SystemAdwareScanner2010_StringsAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_StringsAV.png" alt="Adware.Win32.SystemAdwareScanner2010_StringsAV" width="392" height="1364" /></a></p>
<p>The encryption algorithm is pretty simple, Caesar Cipher using a left rotation of one places.</p>
<p>And here&#8217;s another strings:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Strings.png"><img class="alignnone size-medium wp-image-102" style="border: 1px solid black;" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Strings-400x174.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="174" /></a></p>
<p>The last but not least, we also found this strings:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_StringsKey.png"><img class="alignnone size-full wp-image-103" style="border: 1px solid black;" title="Adware.Win32.SystemAdwareScanner2010_StringsKey" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_StringsKey.png" alt="Adware.Win32.SystemAdwareScanner2010_StringsKey" width="373" height="421" /></a></p>
<p>What is that? Hmmm&#8230;let&#8217;s check it:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Registration.png"><img class="alignnone size-medium wp-image-104" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_Registration-400x298.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="298" /></a></p>
<p>Yes, you&#8217;re right! It is their registration key.</p>
<p>&#8220;<em>System Adware Scanner 2010: Complete protection for everything you do. For only $25.95</em>&#8220;. No, thanks!</p>
<p><strong>Create new files (some name of files/directory are random</strong><strong>):</strong></p>
<ul>
<li>%SystemRoot%\system32\drivers\m4f4a0&#215;0.sys (random)</li>
<li>%AllUsersProfile%\Application Data\m4f4a0&#215;0\m4f4a0&#215;0 (random)</li>
<li>%AllUsersProfile%\Application Data\m4f4a0&#215;0\m4f4a0&#215;0.exe (random)</li>
<li>%AllUsersProfile%\Application Data\m4f4a0&#215;0\m4f4a0&#215;0.i (random)</li>
<li>%UserProfile%\Desktop\System Adware Scanner 2010.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Adware Scanner\System Adware Scanner 2010.lnk</li>
</ul>
<p><strong>Create new registry entries (some name of registry entry are random):</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\m4f4a0&#215;0 (random)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SystemAdwareScanner2010</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\noterminate</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;m4f4a0&#215;0&#8243; (random)</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_ScanResults.png"><img class="alignnone size-medium wp-image-106" title="Adware.Win32.SystemAdwareScanner2010" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_ScanResults-400x298.png" alt="Adware.Win32.SystemAdwareScanner2010" width="400" height="298" /></a><br />
</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_3.png"><img class="alignnone size-full wp-image-83" title="Adware.Win32.SystemAdwareScanner2010_3" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_3.png" alt="Adware.Win32.SystemAdwareScanner2010_3" width="399" height="379" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_1.png"><img class="alignnone size-full wp-image-81" style="border: 1px solid black;" title="Adware.Win32.SystemAdwareScanner2010_1" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SystemAdwareScanner2010_1.png" alt="Adware.Win32.SystemAdwareScanner2010_1" width="298" height="106" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of System Adware Scanner 2010 </span></strong><strong><span style="font-size: small;">(Adware.Win32.SystemAdwareScanner2010</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/29/antivirus-pc-2009-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus PC 2009 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/systemcleanerpro-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemCleanerPro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/malware-defense-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Defense Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Essentials 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/17/system-adware-scanner-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TheDefend Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/16/thedefend-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/16/thedefend-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:03:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[TheDefend]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=66</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the TheDefend adware. a-squared Anti-Malware detects this malware as Adware.Win32.TheDefend.
TheDefend, come from hxxp://www.thedefend.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of TheDefend also made GuardPcs, IGuardPc, SiteAdware, AntiTroy, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the TheDefend adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.TheDefend.</p>
<p>TheDefend, come from hxxp://www.thedefend.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of TheDefend also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, <a href="../post/SafeFighter-Adware-Removal-Instructions.aspx" target="_blank"></a>etc. To further convince victims, TheDefend will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\TheDefend Software\TheDefend\main_config.xml</li>
<li>%ProgramFiles%\TheDefend Software\TheDefend\TheDefend.exe</li>
<li>%ProgramFiles%\TheDefend Software\TheDefend\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\TheDefend.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\TheDefend\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\TheDefend\1 TheDefend.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\TheDefend\2 Homepage.lnk</li>
<li>%UserProfile%\Local Settings\Temp\nsbB.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\TheDefend</li>
<li>HKEY_LOCAL_MACHINE\software\TheDefend</li>
<li>HKEY_CURRENT_USER\software\TheDefend</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;TheDefend&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;TheDefend.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;TheDefend&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img class="alignnone size-medium wp-image-74" title="Adware.Win32.TheDefend_8" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_8-400x295.png" alt="Adware.Win32.TheDefend_8" width="400" height="295" /></p>
<p><img class="alignnone size-full wp-image-73" title="Adware.Win32.TheDefend_7" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_7.png" alt="Adware.Win32.TheDefend_7" width="330" height="216" /></p>
<p><img class="alignnone size-medium wp-image-72" title="Adware.Win32.TheDefend_6" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_6-400x273.png" alt="Adware.Win32.TheDefend_6" width="400" height="273" /></p>
<p><img class="alignnone size-medium wp-image-71" title="Adware.Win32.TheDefend_5" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_5-400x233.png" alt="Adware.Win32.TheDefend_5" width="400" height="233" /></p>
<p><img class="alignnone size-medium wp-image-70" title="Adware.Win32.TheDefend_4" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_4-400x312.png" alt="Adware.Win32.TheDefend_4" width="400" height="312" /></p>
<p><img class="alignnone size-medium wp-image-69" title="Adware.Win32.TheDefend_3" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_3-400x312.png" alt="Adware.Win32.TheDefend_3" width="400" height="312" /></p>
<p><img class="alignnone size-medium wp-image-68" title="Adware.Win32.TheDefend_2" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_2-400x312.png" alt="Adware.Win32.TheDefend_2" width="400" height="312" /></p>
<p><img class="alignnone size-medium wp-image-67" title="Adware.Win32.TheDefend_1" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.TheDefend_1-400x312.png" alt="Adware.Win32.TheDefend_1" width="400" height="312" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of TheDefend </span></strong><strong><span style="font-size: small;">(Adware.Win32.TheDefend</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/18/sysdefence-adware-removal-instructions/" rel="bookmark" class="crp_title">SysDefence Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/21/protectpcs-adware-removal-instructions/" rel="bookmark" class="crp_title">ProtectPcs Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/24/apcprotect-adware-removal-instructions/" rel="bookmark" class="crp_title">APCProtect Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/30/greatdefender-adware-removal-instructions/" rel="bookmark" class="crp_title">GreatDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/04/pcsprotector-adware-removal-instructions/" rel="bookmark" class="crp_title">PcsProtector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/16/thedefend-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GuardPcs Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:17:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[GuardPcs]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=93c1e7d2-e3a8-4c4f-b265-155d2c2d0b91</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the GuardPcs adware. a-squared Anti-Malware detects this malware as Adware.Win32.GuardPcs.
GuardPcs, come from hxxp://www.guardpcs.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of GuardPcs also made TheDefend, IGuardPc, SiteAdware, AntiTroy, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the GuardPcs adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.GuardPcs.</p>
<p>GuardPcs, come from hxxp://www.guardpcs.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of GuardPcs also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, GuardPcs will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\GuardPcs Software\GuardPcs\GuardPcs.exe</li>
<li>%ProgramFiles%\GuardPcs Software\GuardPcs\main_config.xml</li>
<li>%ProgramFiles%\GuardPcs Software\GuardPcs\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\GuardPcs.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardPcs\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardPcs\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\GuardPcs\1 GuardPcs.lnk</li>
<li>%UserProfile%\Local Settings\Temp\nsh4.tmp\nsProcess.dll</li>
<li>%UserProfile%\Local Settings\Temp\nsj2.tmp\time.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\GuardPcs</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\GuardPcs</li>
<li>HKEY_CURRENT_USER\software\GuardPcs</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;GuardPcs&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;GuardPcs.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;GuardPcs&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_10.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.GuardPcs_8.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of GuardPcs </span></strong><strong><span style="font-size: small;">(Adware.Win32.</span></strong><strong><span style="font-size: small;">GuardPc</span></strong><strong><span style="font-size: small;">s)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/" rel="bookmark" class="crp_title">SiteAdware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/" rel="bookmark" class="crp_title">IGuardPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiAdd Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiKeep Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiTroy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IGuardPc Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 20:18:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[IGuardPc]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=6843f23d-0c6e-411b-b3aa-f42f2093ce1e</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the IGuardPc adware. a-squared Anti-Malware detects this malware as Adware.Win32.IGuardPc.
IGuardPc, come from hxxp://www.iguardpc.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of IGuardPc also made TheDefend, GuardPcs, SiteAdware, AntiTroy, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the IGuardPc adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.IGuardPc.</p>
<p>IGuardPc, come from hxxp://www.iguardpc.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of IGuardPc also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, IGuardPc will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\IGuardPc Software\IGuardPc\IGuardPc.exe</li>
<li>%ProgramFiles%\IGuardPc Software\IGuardPc\main_config.xml</li>
<li>%ProgramFiles%\IGuardPc Software\IGuardPc\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\IGuardPc.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\IGuardPc\1 IGuardPc.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\IGuardPc\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\IGuardPc\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\userdemo@iguardpc[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsz4.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE|\software\IGuardPc</li>
<li>HKEY_LOCAL_MACHINE|\software\microsoft\Windows\CurrentVersion\Uninstall\IGuardPc</li>
<li>HKEY_CURRENT_USER|\software\IGuardPc</li>
<li>HKEY_LOCAL_MACHINE|\software\microsoft\Windows\CurrentVersion\Run, &#8220;IGuardPc&#8221;</li>
<li>HKEY_CURRENT_USER|\software\Microsoft\Windows\CurrentVersion\Run, &#8220;IGuardPc.exe&#8221;</li>
<li>HKEY_CURRENT_USER|\software\Microsoft\Windows\CurrentVersion\Run, &#8220;IGuardPc.exe&#8221;</li>
<li>HKEY_CURRENT_USER|\software\Microsoft\Windows\CurrentVersion\Run, &#8220;IGuardPc&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_8.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_10.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.IGuardPC_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of IGuardPc </span></strong><strong><span style="font-size: small;">(Adware.Win32.</span></strong><strong><span style="font-size: small;">IGuardPc</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/" rel="bookmark" class="crp_title">SiteAdware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiAdd Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardPcs Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiKeep Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiTroy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SiteAdware Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 19:21:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SiteAdware]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=d438fb5a-0b32-46c6-b973-edecc30c6edf</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SiteAdware adware. a-squared Anti-Malware detects this malware as Adware.Win32.SiteAdware.
SiteAdware, come from hxxp://www.siteadware.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SiteAdware also made TheDefend, GuardPcs, IGuardPc, AntiTroy, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SiteAdware adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.SiteAdware.</p>
<p>SiteAdware, come from hxxp://www.siteadware.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SiteAdware also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SiteAdware will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SiteAdware Software\SiteAdware\SiteAdware.exe</li>
<li>%ProgramFiles%\SiteAdware Software\SiteAdware\uninstall.exe</li>
<li>%ProgramFiles%\SiteAdware Software\SiteAdware\main_config.xml</li>
<li>%AllUsersProfile%\Desktop\SiteAdware.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteAdware\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteAdware\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteAdware\1 SiteAdware.lnk</li>
<li>%UserProfile%\Local Settings\Temp\nseA.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SiteAdware</li>
<li>HKEY_LOCAL_MACHINE\software\SiteAdware</li>
<li>HKEY_CURRENT_USER\software\SiteAdware</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SiteAdware&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SiteAdware.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SiteAdware&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_8.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_10.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SiteAdware_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of SiteAdware</span></strong><strong><span style="font-size: small;"> </span></strong><strong><span style="font-size: small;">(Adware.Win32.SiteAdware)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiAdd Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/" rel="bookmark" class="crp_title">IGuardPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiKeep Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardPcs Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiTroy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safety Anti-Spyware Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 19:08:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=6d1a3d51-c142-46d0-ac17-5b053480e730</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Safety Anti-Spyware adware. a-squared Anti-Malware detects this malware as Adware.Win32.SafetyAntiSpyware.
Safety Anti-Spyware, come from hxxp://safetyantispywareshop.com, is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Safety Anti-Spyware adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.SafetyAntiSpyware.</p>
<p>Safety Anti-Spyware, come from hxxp://safetyantispywareshop.com, is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Safety Anti-Spyware 3\Safety Anti-Spyware 3.exe</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Safety Anti-Spyware 3.lnk</li>
<li>%UserProfile%\Desktop\Safety Anti-Spyware 3.lnk</li>
<li>%UserProfile%\Start Menu\Safety Anti-Spyware 3\Safety Anti-Spyware 3.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\B449DC9C39F1FF5AE14979CE086BB3CA</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Safety Anti-Spyware 3</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Safety Anti-Spyware 3&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SafetyAntispyware_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SafetyAntispyware_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.SafetyAntispyware_3.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Safety Anti-Spyware</span></strong><strong><span style="font-size: small;"> </span></strong><strong><span style="font-size: small;">(Adware.Win32.SafetyAntiSpyware)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Professional Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeAntivir Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Security Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Security 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 18:39:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=da647c6f-1e05-4ec2-b26a-42836adfdbae</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Internet Security 2010 adware. a-squared Anti-Malware detects this malware as Adware.Win32.InternetSecurity2010.
Internet Security 2010 is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Internet Security 2010 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.InternetSecurity2010.</p>
<p>Internet Security 2010 is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\InternetSecurity2010\IS2010.exe</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk</li>
<li>%UserProfile%\Desktop\Internet Security 2010.lnk</li>
<li>%UserProfile%\Start Menu\Internet Security 2010.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\IS2010</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Internet Security 2010&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.InternetSecurity2010_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.InternetSecurity2010_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.InternetSecurity2010_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.InternetSecurity2010_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.InternetSecurity2010_5.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of </span></strong><strong><span style="font-size: small;">Internet Security 2010 </span></strong><strong><span style="font-size: small;">(Adware.Win32.InternetSecurity2010)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/" rel="bookmark" class="crp_title">Safety Anti-Spyware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/15/security-essentials-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Essentials 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Professional Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeAntivir Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Live PC Care Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/08/live-pc-care-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/08/live-pc-care-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 16:55:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Live PC Care]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=85</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Live PC Care adware. a-squared Anti-Malware detects this malware as Adware.Win32.LivePCCare.
Live PC Care (hxxp://livepcguard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: PC Live Guard, Additional Guard, Enterprise Suite, System Defender, Windows [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Live PC Care adware. <a href="http://www.emsisoft.com/en/software/antimalware/" target="_blank">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LivePCCare" target="_blank">Adware.Win32.LivePCCare</a>.</p>
<p>Live PC Care (hxxp://livepcguard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCLiveGuard" target="_blank">PC Live Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdditionalGuard" target="_blank">Additional Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EnterpriseSuite" target="_blank">Enterprise Suite</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefender" target="_blank">System Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEnterpriseDefender">Windows Enterprise Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCDefender">Windows PC Defender</a>, etc. This adware create numerous junk files on your computer, usually at Recent folder, that are used to impersonate malware files. Once the program is running it will scan your computer and then display these files as infections, but will not allow you to remove them until you purchase the program.</p>
<p><strong>The main program will extract several files to (some name of the files and directory for this rogue are random):</strong></p>
<ul>
<li>%SystemRoot%\system32\DOSX.EXE</li>
<li>%SystemRoot%\system32\HIMEM.SYS</li>
<li>%SystemRoot%\system32\MSCDEXNT.EXE</li>
<li>%SystemRoot%\system32\REDIR.EXE</li>
<li>%SystemRoot%\system32\COMMAND.COM</li>
<li>%SystemRoot%\system32\drivers\etc\hosts</li>
<li>%AllUsersProfile%\Application Data\58969\LPCG.ico</li>
<li>%AllUsersProfile%\Application Data\58969\LPf4c.exe</li>
<li>%AllUsersProfile%\Application Data\LPCGSys\lpcg.cfg</li>
<li>%UserProfile%\Application Data\Live PC Care\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Live PC Care\Instructions.ini</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Live PC Care.lnk</li>
<li>%UserProfile%\Desktop\Live PC Care.lnk</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Recent\energy.tmp</li>
<li>%UserProfile%\Recent\exec.drv</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\fan.dll</li>
<li>%UserProfile%\Recent\fan.drv</li>
<li>%UserProfile%\Recent\fan.exe</li>
<li>%UserProfile%\Recent\FS.dll</li>
<li>%UserProfile%\Recent\gid.sys</li>
<li>%UserProfile%\Recent\kernel32.sys</li>
<li>%UserProfile%\Recent\pal.dll</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\runddl.dll</li>
<li>%UserProfile%\Recent\runddlkey.tmp</li>
<li>%UserProfile%\Recent\ANTIGEN.drv</li>
<li>%UserProfile%\Start Menu\Live PC Care.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Live PC Care.lnk</li>
</ul>
<p>Create new registry entries:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_aa215.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_aa215.DocHostUIHandler\Clsid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Live PC Care&#8221;</li>
</ul>
<p><strong>This rogue application also changes the hosts file:</strong></p>
<ul>
<li>127.0.0.1 localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>89.248.168.186 google.ae</li>
<li>89.248.168.186 google.as</li>
<li>89.248.168.186 google.at</li>
<li>89.248.168.186 google.az</li>
<li>89.248.168.186 google.ba</li>
<li>89.248.168.186 google.be</li>
<li>89.248.168.186 google.bg</li>
<li>89.248.168.186 google.bs</li>
<li>89.248.168.186 google.ca</li>
<li>89.248.168.186 google.cd</li>
<li>89.248.168.186 google.com.gh</li>
<li>89.248.168.186 google.com.hk</li>
<li>89.248.168.186 google.com.jm</li>
<li>89.248.168.186 google.com.mx</li>
<li>89.248.168.186 google.com.my</li>
<li>89.248.168.186 google.com.na</li>
<li>89.248.168.186 google.com.nf</li>
<li>89.248.168.186 google.com.ng</li>
<li>89.248.168.186 google.ch</li>
<li>89.248.168.186 google.com.np</li>
<li>89.248.168.186 google.com.pr</li>
<li>89.248.168.186 google.com.qa</li>
<li>89.248.168.186 google.com.sg</li>
<li>89.248.168.186 google.com.tj</li>
<li>89.248.168.186 google.com.tw</li>
<li>89.248.168.186 google.dj</li>
<li>89.248.168.186 google.de</li>
<li>89.248.168.186 google.dk</li>
<li>89.248.168.186 google.dm</li>
<li>89.248.168.186 google.ee</li>
<li>89.248.168.186 google.fi</li>
<li>89.248.168.186 google.fm</li>
<li>89.248.168.186 google.fr</li>
<li>89.248.168.186 google.ge</li>
<li>89.248.168.186 google.gg</li>
<li>89.248.168.186 google.gm</li>
<li>89.248.168.186 google.gr</li>
<li>89.248.168.186 google.ht</li>
<li>89.248.168.186 google.ie</li>
<li>89.248.168.186 google.im</li>
<li>89.248.168.186 google.in</li>
<li>89.248.168.186 google.it</li>
<li>89.248.168.186 google.ki</li>
<li>89.248.168.186 google.la</li>
<li>89.248.168.186 google.li</li>
<li>89.248.168.186 google.lv</li>
<li>89.248.168.186 google.ma</li>
<li>89.248.168.186 google.ms</li>
<li>89.248.168.186 google.mu</li>
<li>89.248.168.186 google.mw</li>
<li>89.248.168.186 google.nl</li>
<li>89.248.168.186 google.no</li>
<li>89.248.168.186 google.nr</li>
<li>89.248.168.186 google.nu</li>
<li>89.248.168.186 google.pl</li>
<li>89.248.168.186 google.pn</li>
<li>89.248.168.186 google.pt</li>
<li>89.248.168.186 google.ro</li>
<li>89.248.168.186 google.ru</li>
<li>89.248.168.186 google.rw</li>
<li>89.248.168.186 google.sc</li>
<li>89.248.168.186 google.se</li>
<li>89.248.168.186 google.sh</li>
<li>89.248.168.186 google.si</li>
<li>89.248.168.186 google.sm</li>
<li>89.248.168.186 google.sn</li>
<li>89.248.168.186 google.st</li>
<li>89.248.168.186 google.tl</li>
<li>89.248.168.186 google.tm</li>
<li>89.248.168.186 google.tt</li>
<li>89.248.168.186 google.us</li>
<li>89.248.168.186 google.vu</li>
<li>89.248.168.186 google.ws</li>
<li>89.248.168.186 google.co.ck</li>
<li>89.248.168.186 google.co.id</li>
<li>89.248.168.186 google.co.il</li>
<li>89.248.168.186 google.co.in</li>
<li>89.248.168.186 google.co.jp</li>
<li>89.248.168.186 google.co.kr</li>
<li>89.248.168.186 google.co.ls</li>
<li>89.248.168.186 google.co.ma</li>
<li>89.248.168.186 google.co.nz</li>
<li>89.248.168.186 google.co.tz</li>
<li>89.248.168.186 google.co.ug</li>
<li>89.248.168.186 google.co.uk</li>
<li>89.248.168.186 google.co.za</li>
<li>89.248.168.186 google.co.zm</li>
<li>89.248.168.186 google.com</li>
<li>89.248.168.186 google.com.af</li>
<li>89.248.168.186 google.com.ag</li>
<li>89.248.168.186 google.com.ar</li>
<li>89.248.168.186 google.com.au</li>
<li>89.248.168.186 google.com.bn</li>
<li>89.248.168.186 google.com.br</li>
<li>89.248.168.186 google.com.by</li>
<li>89.248.168.186 google.com.bz</li>
<li>89.248.168.186 google.com.cu</li>
<li>89.248.168.186 google.com.ec</li>
<li>89.248.168.186 google.com.fj</li>
<li>89.248.168.186 www.google.ae</li>
<li>89.248.168.186 www.google.as</li>
<li>89.248.168.186 www.google.at</li>
<li>89.248.168.186 www.google.az</li>
<li>89.248.168.186 www.google.ba</li>
<li>89.248.168.186 www.google.be</li>
<li>89.248.168.186 www.google.bg</li>
<li>89.248.168.186 www.google.bs</li>
<li>89.248.168.186 www.google.ca</li>
<li>89.248.168.186 www.google.cd</li>
<li>89.248.168.186 www.google.com.gh</li>
<li>89.248.168.186 www.google.com.hk</li>
<li>89.248.168.186 www.google.com.jm</li>
<li>89.248.168.186 www.google.com.mx</li>
<li>89.248.168.186 www.google.com.my</li>
<li>89.248.168.186 www.google.com.na</li>
<li>89.248.168.186 www.google.com.nf</li>
<li>89.248.168.186 www.google.com.ng</li>
<li>89.248.168.186 www.google.ch</li>
<li>89.248.168.186 www.google.com.np</li>
<li>89.248.168.186 www.google.com.pr</li>
<li>89.248.168.186 www.google.com.qa</li>
<li>89.248.168.186 www.google.com.sg</li>
<li>89.248.168.186 www.google.com.tj</li>
<li>89.248.168.186 www.google.com.tw</li>
<li>89.248.168.186 www.google.dj</li>
<li>89.248.168.186 www.google.de</li>
<li>89.248.168.186 www.google.dk</li>
<li>89.248.168.186 www.google.dm</li>
<li>89.248.168.186 www.google.ee</li>
<li>89.248.168.186 www.google.fi</li>
<li>89.248.168.186 www.google.fm</li>
<li>89.248.168.186 www.google.fr</li>
<li>89.248.168.186 www.google.ge</li>
<li>89.248.168.186 www.google.gg</li>
<li>89.248.168.186 www.google.gm</li>
<li>89.248.168.186 www.google.gr</li>
<li>89.248.168.186 www.google.ht</li>
<li>89.248.168.186 www.google.ie</li>
<li>89.248.168.186 www.google.im</li>
<li>89.248.168.186 www.google.in</li>
<li>89.248.168.186 www.google.it</li>
<li>89.248.168.186 www.google.ki</li>
<li>89.248.168.186 www.google.la</li>
<li>89.248.168.186 www.google.li</li>
<li>89.248.168.186 www.google.lv</li>
<li>89.248.168.186 www.google.ma</li>
<li>89.248.168.186 www.google.ms</li>
<li>89.248.168.186 www.google.mu</li>
<li>89.248.168.186 www.google.mw</li>
<li>89.248.168.186 www.google.nl</li>
<li>89.248.168.186 www.google.no</li>
<li>89.248.168.186 www.google.nr</li>
<li>89.248.168.186 www.google.nu</li>
<li>89.248.168.186 www.google.pl</li>
<li>89.248.168.186 www.google.pn</li>
<li>89.248.168.186 www.google.pt</li>
<li>89.248.168.186 www.google.ro</li>
<li>89.248.168.186 www.google.ru</li>
<li>89.248.168.186 www.google.rw</li>
<li>89.248.168.186 www.google.sc</li>
<li>89.248.168.186 www.google.se</li>
<li>89.248.168.186 www.google.sh</li>
<li>89.248.168.186 www.google.si</li>
<li>89.248.168.186 www.google.sm</li>
<li>89.248.168.186 www.google.sn</li>
<li>89.248.168.186 www.google.st</li>
<li>89.248.168.186 www.google.tl</li>
<li>89.248.168.186 www.google.tm</li>
<li>89.248.168.186 www.google.tt</li>
<li>89.248.168.186 www.google.us</li>
<li>89.248.168.186 www.google.vu</li>
<li>89.248.168.186 www.google.ws</li>
<li>89.248.168.186 www.google.co.ck</li>
<li>89.248.168.186 www.google.co.id</li>
<li>89.248.168.186 www.google.co.il</li>
<li>89.248.168.186 www.google.co.in</li>
<li>89.248.168.186 www.google.co.jp</li>
<li>89.248.168.186 www.google.co.kr</li>
<li>89.248.168.186 www.google.co.ls</li>
<li>89.248.168.186 www.google.co.ma</li>
<li>89.248.168.186 www.google.co.nz</li>
<li>89.248.168.186 www.google.co.tz</li>
<li>89.248.168.186 www.google.co.ug</li>
<li>89.248.168.186 www.google.co.uk</li>
<li>89.248.168.186 www.google.co.za</li>
<li>89.248.168.186 www.google.co.zm</li>
<li>89.248.168.186 www.google.com</li>
<li>89.248.168.186 www.google.com.af</li>
<li>89.248.168.186 www.google.com.ag</li>
<li>89.248.168.186 www.google.com.ar</li>
<li>89.248.168.186 www.google.com.au</li>
<li>89.248.168.186 www.google.com.bn</li>
<li>89.248.168.186 www.google.com.br</li>
<li>89.248.168.186 www.google.com.by</li>
<li>89.248.168.186 www.google.com.bz</li>
<li>89.248.168.186 www.google.com.cu</li>
<li>89.248.168.186 www.google.com.ec</li>
<li>89.248.168.186 www.google.com.fj</li>
<li>89.248.168.186 google.com</li>
<li>89.248.168.186 www.google.com</li>
<li>89.248.168.186 bing.com</li>
<li>89.248.168.186 www.bing.com</li>
<li>89.248.168.186 search.yahoo.com</li>
<li>89.248.168.186 www.search.yahoo.com</li>
<li>89.248.168.186 search.live.com</li>
<li>89.248.168.186 search.msn.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_1.png"><img class="alignnone" title="Adware.Win32.LivePCCare" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_1.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_2.png"><img class="alignnone" title="Adware.Win32.LivePCCare" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_2.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_3.png"><img class="alignnone" title="Adware.Win32.LivePCCare" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_3.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_4.png"><img class="alignnone" title="Adware.Win32.LivePCCare" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_4.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_5.png"><img class="alignnone" title="Adware.Win32.LivePCCare" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.LivePCCare_5.png" alt="" width="400" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of Live PC Care </span></strong><strong><span style="font-size: small;">(Adware.Win32.LivePCCare</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Live Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/08/live-pc-care-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PC Live Guard Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 16:36:17 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PC Live Guard]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=88</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the PC Live Guard adware. a-squared Anti-Malware detects this malware as Adware.Win32.PCLiveGuard.
PC Live Guard (hxxp://pcliveguard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: Live PC Care, Additional Guard, Enterprise Suite, System Defender, Windows [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the PC Live Guard adware. <a href="http://www.emsisoft.com/en/software/antimalware/" target="_blank">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCLiveGuard" target="_blank">Adware.Win32.PCLiveGuard</a>.</p>
<p>PC Live Guard (hxxp://pcliveguard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LivePCCare" target="_blank">Live PC Care</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdditionalGuard" target="_blank">Additional Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EnterpriseSuite" target="_blank">Enterprise Suite</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefender" target="_blank">System Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEnterpriseDefender">Windows Enterprise Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCDefender">Windows PC Defender</a>, etc. This adware create numerous junk files on your computer, usually at Recent folder, that are used to impersonate malware files. Once the program is running it will scan your computer and then display these files as infections, but will not allow you to remove them until you purchase the program.</p>
<p><strong>The main program will extract several files to (some name of the files and directory for this rogue are random):</strong></p>
<ul>
<li>%SystemRoot%\system32\COMMAND.COM</li>
<li>%SystemRoot%\system32\DOSX.EXE</li>
<li>%SystemRoot%\system32\HIMEM.SYS</li>
<li>%SystemRoot%\system32\MSCDEXNT.EXE</li>
<li>%SystemRoot%\system32\REDIR.EXE</li>
<li>%SystemRoot%\system32\drivers\etc\hosts</li>
<li>%AllUsersProfile%\Application Data\58969\PCLG.ico</li>
<li>%AllUsersProfile%\Application Data\58969\PCf4c.exe</li>
<li>%AllUsersProfile%\Application Data\PCOSOXTLLG\PCYKMWLG.cfg</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Live Guard.lnk</li>
<li>%UserProfile%\Application Data\PC Live Guard\Instructions.ini</li>
<li>%UserProfile%\Application Data\PC Live Guard\cookies.sqlite</li>
<li>%UserProfile%\Desktop\PC Live Guard.lnk</li>
<li>%UserProfile%\Recent\ddv.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\fix.drv</li>
<li>%UserProfile%\Recent\gid.exe</li>
<li>%UserProfile%\Recent\grid.dll</li>
<li>%UserProfile%\Recent\pal.dll</li>
<li>%UserProfile%\Recent\pal.exe</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\PE.sys</li>
<li>%UserProfile%\Recent\SICKBOY.sys</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Recent\cb.drv</li>
<li>%UserProfile%\Start Menu\PC Live Guard.lnk</li>
<li>%UserProfile%\Start Menu\Programs\PC Live Guard.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_a1147.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_a1147.DocHostUIHandler\Clsid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;PC Live Guard&#8221;</li>
</ul>
<p><strong>This rogue application also changes the hosts file:</strong></p>
<p>127.0.0.1 localhost<br />
74.125.45.100 4-open-davinci.com<br />
74.125.45.100 securitysoftwarepayments.com<br />
74.125.45.100 privatesecuredpayments.com<br />
74.125.45.100 secure.privatesecuredpayments.com<br />
74.125.45.100 getantivirusplusnow.com<br />
74.125.45.100 secure-plus-payments.com<br />
74.125.45.100 www.getantivirusplusnow.com<br />
74.125.45.100 www.secure-plus-payments.com<br />
74.125.45.100 www.getavplusnow.com<br />
74.125.45.100 safebrowsing-cache.google.com<br />
74.125.45.100 urs.microsoft.com<br />
74.125.45.100 www.securesoftwarebill.com<br />
74.125.45.100 secure.paysecuresystem.com<br />
74.125.45.100 paysoftbillsolution.com<br />
74.125.45.100 protected.maxisoftwaremart.com<br />
93.174.89.11 google.ae<br />
93.174.89.11 google.as<br />
93.174.89.11 google.at<br />
93.174.89.11 google.az<br />
93.174.89.11 google.ba<br />
93.174.89.11 google.be<br />
93.174.89.11 google.bg<br />
93.174.89.11 google.bs<br />
93.174.89.11 google.ca<br />
93.174.89.11 google.cd<br />
93.174.89.11 google.com.gh<br />
93.174.89.11 google.com.hk<br />
93.174.89.11 google.com.jm<br />
93.174.89.11 google.com.mx<br />
93.174.89.11 google.com.my<br />
93.174.89.11 google.com.na<br />
93.174.89.11 google.com.nf<br />
93.174.89.11 google.com.ng<br />
93.174.89.11 google.ch<br />
93.174.89.11 google.com.np<br />
93.174.89.11 google.com.pr<br />
93.174.89.11 google.com.qa<br />
93.174.89.11 google.com.sg<br />
93.174.89.11 google.com.tj<br />
93.174.89.11 google.com.tw<br />
93.174.89.11 google.dj<br />
93.174.89.11 google.de<br />
93.174.89.11 google.dk<br />
93.174.89.11 google.dm<br />
93.174.89.11 google.ee<br />
93.174.89.11 google.fi<br />
93.174.89.11 google.fm<br />
93.174.89.11 google.fr<br />
93.174.89.11 google.ge<br />
93.174.89.11 google.gg<br />
93.174.89.11 google.gm<br />
93.174.89.11 google.gr<br />
93.174.89.11 google.ht<br />
93.174.89.11 google.ie<br />
93.174.89.11 google.im<br />
93.174.89.11 google.in<br />
93.174.89.11 google.it<br />
93.174.89.11 google.ki<br />
93.174.89.11 google.la<br />
93.174.89.11 google.li<br />
93.174.89.11 google.lv<br />
93.174.89.11 google.ma<br />
93.174.89.11 google.ms<br />
93.174.89.11 google.mu<br />
93.174.89.11 google.mw<br />
93.174.89.11 google.nl<br />
93.174.89.11 google.no<br />
93.174.89.11 google.nr<br />
93.174.89.11 google.nu<br />
93.174.89.11 google.pl<br />
93.174.89.11 google.pn<br />
93.174.89.11 google.pt<br />
93.174.89.11 google.ro<br />
93.174.89.11 google.ru<br />
93.174.89.11 google.rw<br />
93.174.89.11 google.sc<br />
93.174.89.11 google.se<br />
93.174.89.11 google.sh<br />
93.174.89.11 google.si<br />
93.174.89.11 google.sm<br />
93.174.89.11 google.sn<br />
93.174.89.11 google.st<br />
93.174.89.11 google.tl<br />
93.174.89.11 google.tm<br />
93.174.89.11 google.tt<br />
93.174.89.11 google.us<br />
93.174.89.11 google.vu<br />
93.174.89.11 google.ws<br />
93.174.89.11 google.co.ck<br />
93.174.89.11 google.co.id<br />
93.174.89.11 google.co.il<br />
93.174.89.11 google.co.in<br />
93.174.89.11 google.co.jp<br />
93.174.89.11 google.co.kr<br />
93.174.89.11 google.co.ls<br />
93.174.89.11 google.co.ma<br />
93.174.89.11 google.co.nz<br />
93.174.89.11 google.co.tz<br />
93.174.89.11 google.co.ug<br />
93.174.89.11 google.co.uk<br />
93.174.89.11 google.co.za<br />
93.174.89.11 google.co.zm<br />
93.174.89.11 google.com<br />
93.174.89.11 google.com.af<br />
93.174.89.11 google.com.ag<br />
93.174.89.11 google.com.ar<br />
93.174.89.11 google.com.au<br />
93.174.89.11 google.com.bn<br />
93.174.89.11 google.com.br<br />
93.174.89.11 google.com.by<br />
93.174.89.11 google.com.bz<br />
93.174.89.11 google.com.cu<br />
93.174.89.11 google.com.ec<br />
93.174.89.11 google.com.fj<br />
93.174.89.11 www.google.ae<br />
93.174.89.11 www.google.as<br />
93.174.89.11 www.google.at<br />
93.174.89.11 www.google.az<br />
93.174.89.11 www.google.ba<br />
93.174.89.11 www.google.be<br />
93.174.89.11 www.google.bg<br />
93.174.89.11 www.google.bs<br />
93.174.89.11 www.google.ca<br />
93.174.89.11 www.google.cd<br />
93.174.89.11 www.google.com.gh<br />
93.174.89.11 www.google.com.hk<br />
93.174.89.11 www.google.com.jm<br />
93.174.89.11 www.google.com.mx<br />
93.174.89.11 www.google.com.my<br />
93.174.89.11 www.google.com.na<br />
93.174.89.11 www.google.com.nf<br />
93.174.89.11 www.google.com.ng<br />
93.174.89.11 www.google.ch<br />
93.174.89.11 www.google.com.np<br />
93.174.89.11 www.google.com.pr<br />
93.174.89.11 www.google.com.qa<br />
93.174.89.11 www.google.com.sg<br />
93.174.89.11 www.google.com.tj<br />
93.174.89.11 www.google.com.tw<br />
93.174.89.11 www.google.dj<br />
93.174.89.11 www.google.de<br />
93.174.89.11 www.google.dk<br />
93.174.89.11 www.google.dm<br />
93.174.89.11 www.google.ee<br />
93.174.89.11 www.google.fi<br />
93.174.89.11 www.google.fm<br />
93.174.89.11 www.google.fr<br />
93.174.89.11 www.google.ge<br />
93.174.89.11 www.google.gg<br />
93.174.89.11 www.google.gm<br />
93.174.89.11 www.google.gr<br />
93.174.89.11 www.google.ht<br />
93.174.89.11 www.google.ie<br />
93.174.89.11 www.google.im<br />
93.174.89.11 www.google.in<br />
93.174.89.11 www.google.it<br />
93.174.89.11 www.google.ki<br />
93.174.89.11 www.google.la<br />
93.174.89.11 www.google.li<br />
93.174.89.11 www.google.lv<br />
93.174.89.11 www.google.ma<br />
93.174.89.11 www.google.ms<br />
93.174.89.11 www.google.mu<br />
93.174.89.11 www.google.mw<br />
93.174.89.11 www.google.nl<br />
93.174.89.11 www.google.no<br />
93.174.89.11 www.google.nr<br />
93.174.89.11 www.google.nu<br />
93.174.89.11 www.google.pl<br />
93.174.89.11 www.google.pn<br />
93.174.89.11 www.google.pt<br />
93.174.89.11 www.google.ro<br />
93.174.89.11 www.google.ru<br />
93.174.89.11 www.google.rw<br />
93.174.89.11 www.google.sc<br />
93.174.89.11 www.google.se<br />
93.174.89.11 www.google.sh<br />
93.174.89.11 www.google.si<br />
93.174.89.11 www.google.sm<br />
93.174.89.11 www.google.sn<br />
93.174.89.11 www.google.st<br />
93.174.89.11 www.google.tl<br />
93.174.89.11 www.google.tm<br />
93.174.89.11 www.google.tt<br />
93.174.89.11 www.google.us<br />
93.174.89.11 www.google.vu<br />
93.174.89.11 www.google.ws<br />
93.174.89.11 www.google.co.ck<br />
93.174.89.11 www.google.co.id<br />
93.174.89.11 www.google.co.il<br />
93.174.89.11 www.google.co.in<br />
93.174.89.11 www.google.co.jp<br />
93.174.89.11 www.google.co.kr<br />
93.174.89.11 www.google.co.ls<br />
93.174.89.11 www.google.co.ma<br />
93.174.89.11 www.google.co.nz<br />
93.174.89.11 www.google.co.tz<br />
93.174.89.11 www.google.co.ug<br />
93.174.89.11 www.google.co.uk<br />
93.174.89.11 www.google.co.za<br />
93.174.89.11 www.google.co.zm<br />
93.174.89.11 www.google.com<br />
93.174.89.11 www.google.com.af<br />
93.174.89.11 www.google.com.ag<br />
93.174.89.11 www.google.com.ar<br />
93.174.89.11 www.google.com.au<br />
93.174.89.11 www.google.com.bn<br />
93.174.89.11 www.google.com.br<br />
93.174.89.11 www.google.com.by<br />
93.174.89.11 www.google.com.bz<br />
93.174.89.11 www.google.com.cu<br />
93.174.89.11 www.google.com.ec<br />
93.174.89.11 www.google.com.fj<br />
93.174.89.11 google.com<br />
93.174.89.11 www.google.com<br />
93.174.89.11 bing.com<br />
93.174.89.11 www.bing.com<br />
93.174.89.11 search.yahoo.com<br />
93.174.89.11 www.search.yahoo.com<br />
93.174.89.11 search.live.com<br />
93.174.89.11 search.msn.com</p>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_1.png"><img class="alignnone" title="Adware.Win32.PCLiveGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_1.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_2.png"><img class="alignnone" title="Adware.Win32.PCLiveGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_2.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_3.png"><img class="alignnone" title="Adware.Win32.PCLiveGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_3.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_4.png"><img class="alignnone" title="Adware.Win32.PCLiveGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PCLiveGuard_4.png" alt="" width="400" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of PC Live Guard </span></strong><strong><span style="font-size: small;">(Adware.Win32.</span></strong><strong><span style="font-size: small;">PCLiveGuard</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiTroy Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 17:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntiTroy]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=d5035499-a56a-4d8f-b18e-317b0a376bde</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the AntiTroy adware. a-squared Anti-Malware detects this malware as Adware.Win32.AntiTroy.
AntiTroy, come from antitroy.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiTroy also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the AntiTroy adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">Adware.Win32.AntiTroy</a>.</p>
<p>AntiTroy, come from antitroy.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiTroy also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, AntiTroy will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\AntiTroy Software\AntiTroy\AntiTroy.exe</li>
<li>%ProgramFiles%\AntiTroy Software\AntiTroy\main_config.xml</li>
<li>%ProgramFiles%\AntiTroy Software\AntiTroy\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\AntiTroy.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiTroy\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiTroy\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiTroy\1 AntiTroy.lnk</li>
<li>%UserProfile%\Cookies\userdemo@antitroy[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsg19.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE|\software\AntiTroy</li>
<li>HKEY_LOCAL_MACHINE|\software\microsoft\Windows\CurrentVersion\Uninstall\AntiTroy</li>
<li>HKEY_CURRENT_USER|\software\AntiTroy</li>
<li>HKEY_LOCAL_MACHINE|\software\microsoft\Windows\CurrentVersion\Run, &#8220;AntiTroy&#8221;</li>
<li>HKEY_CURRENT_USER|\software\Microsoft\Windows\CurrentVersion\Run, &#8220;AntiTroy.exe&#8221;</li>
<li>HKEY_CURRENT_USER|\software\Microsoft\Windows\CurrentVersion\Run, &#8220;AntiTroy&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_8.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_10.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiTroy_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.AntiTroy?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiAdd Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiKeep Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/" rel="bookmark" class="crp_title">SiteAdware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/" rel="bookmark" class="crp_title">IGuardPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/15/guardpcs-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardPcs Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiKeep Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 17:56:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntiKeep]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=e2c23986-439b-460b-9ce4-3f64c53e7397</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the AntiKeep adware. a-squared Anti-Malware detects this malware as Adware.Win32.AntiKeep.
AntiKeep, come from antikeep.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiKeep also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the AntiKeep adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">Adware.Win32.AntiKeep</a>.</p>
<p>AntiKeep, come from antikeep.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiKeep also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, AntiKeep will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\AntiKeep Software\AntiKeep\uninstall.exe</li>
<li>%ProgramFiles%\AntiKeep Software\AntiKeep\AntiKeep.exe</li>
<li>%AllUsersProfile%\Desktop\AntiKeep.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiKeep\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiKeep\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiKeep\1 AntiKeep.lnk</li>
<li>%UserProfile%\Cookies\userdemo@antikeep[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsr12.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\AntiKeep</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\AntiKeep</li>
<li>HKEY_CURRENT_USER\software\AntiKeep</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;AntiKeep.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_8.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_10.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiKeep_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.AntiKeep?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiAdd Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiTroy Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/" rel="bookmark" class="crp_title">SiteAdware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/" rel="bookmark" class="crp_title">IGuardPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Personal Security Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 17:49:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=19ec5b68-44a4-43d1-9602-0c73aea8c088</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Personal Security adware. a-squared Anti-Malware detects this malware as Adware.Win32.PersonalSecurity.
Personal Security is a new rogue scanner program. It shows fake warning messages, shows misleading scan results, and fake security alerts, to convince the user that their computer infected with malware. The author [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Personal Security adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PersonalSecurity" target="_blank">Adware.Win32.PersonalSecurity</a>.</p>
<p>Personal Security is a new rogue scanner program. It shows fake warning messages, shows misleading scan results, and fake security alerts, to convince the user that their computer infected with malware. The author of Personal Security also have made another rogue applications, such as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CyberSecurity" target="_blank">Cyber Security</a> and TotalSecurity. Additional, Personal Security will also install a new BHO (Browser Helper Objects) on the victim machine.</p>
<p>This rogue scanner also has the ability to avoid Virtual Machine, so, it won&#8217;t run on the virtual environments, and will displays fake error messages.</p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_FakeError.png" alt="" /></p>
<p>Once the installer file is clicked, it will immediately download other file from this address:</p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_Address.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_7.png" alt="" /></p>
<p>After installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\PSecurity\psecurity.exe</li>
<li>%ProgramFiles%\Common Files\PSecurityUninstall\Uninstall.lnk</li>
<li>%SystemRoot%\system32\win32extension.dll</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Help.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Personal Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Registration.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Security Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Settings.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Update.lnk</li>
<li>%AllUsersProfile%\Start Menu\PSecurity\Computer Scan.lnk</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSecurity.lnk</li>
<li>%UserProfile%\Desktop\Personal Security.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\256537C7AD95AFE5C50084ABD7767AE9</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\PSecurity</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;PSecurity&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.PersonalSecurity_6.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.PersonalSecurity?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/10/14/cyber-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Cyber Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/21/alpha-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Alpha Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeAntivir Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiAdd Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 17:37:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[AntiAdd]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=768959c7-288c-47d6-b305-3e7a55647d96</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the AntiAdd adware. a-squared Anti-Malware detects this malware as Adware.Win32.AntiAdd.
AntiAdd, come from antiadd.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiAdd also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the AntiAdd adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">Adware.Win32.AntiAdd</a>.</p>
<p>AntiAdd, come from antiadd.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of AntiAdd also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, AntiAdd will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\AntiAdd Software\AntiAdd\AntiAdd.exe</li>
<li>%ProgramFiles%\AntiAdd Software\AntiAdd\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\AntiAdd.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiAdd\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiAdd\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\AntiAdd\1 AntiAdd.lnk</li>
<li>%UserProfile%\Cookies\userdemo@antiadd[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsc2.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\AntiAdd</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\AntiAdd</li>
<li>HKEY_CURRENT_USER\software\AntiAdd</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_7.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_8.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_9.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.AntiAdd_10.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.AntiAdd?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/03/antikeep-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiKeep Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/antitroy-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiTroy Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/10/siteadware-adware-removal-instructions/" rel="bookmark" class="crp_title">SiteAdware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/11/iguardpc-adware-removal-instructions/" rel="bookmark" class="crp_title">IGuardPc Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/01/antiadd-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FakeAntivir Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 06:12:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=4e61fead-cd97-47b9-9752-b1b32ad84760</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the FakeAntivir adware. a-squared Anti-Malware detects this malware as Adware.Win32.FakeAntivir.
FakeAntivir is an new rogue scanner program named &#8220;Antivir&#8221;. It shows fake warning messages, shows misleading scan results, and fake security alerts to convince the user that their computer infected with malware. This rogue [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the FakeAntivir adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.FakeAntivir.</p>
<p>FakeAntivir is an new rogue scanner program named &#8220;Antivir&#8221;. It shows fake warning messages, shows misleading scan results, and fake security alerts to convince the user that their computer infected with malware. This rogue scanner has the ability to avoid Virtual Machine, so, it won&#8217;t run on the virtual environments, and will displays fake error messages.</p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_FakeMessages.png" alt="" /></p>
<p>Once the installer file is clicked, it will immediately download other file from this address:</p>
<ul>
<li>hxxp://winupdateserver2.com</li>
</ul>
<p>After installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p>Create new files:</p>
<ul>
<li>%ProgramFiles%\AV\antivir.exe</li>
<li>%ProgramFiles%\Common Files\Uninstall\AV\Uninstall.lnk</li>
<li>%SystemRoot%\system32\UpdateCheck.dll</li>
<li>%AllUsersProfile%\Start Menu\AV\Antivir.lnk</li>
<li>%AllUsersProfile%\Start Menu\AV\Uninstall.lnk</li>
<li>%UserProfile%\Desktop\Antivir.lnk</li>
</ul>
<p>Create new registry entry:</p>
<ul>
<li>HKEY_CURRENT_USER\software\EVA50C</li>
</ul>
<p>Screenshots:</p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_4.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_6.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/12/Adware.Win32.FakeAntivir_7.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.FakeAntivir?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Professional Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/" rel="bookmark" class="crp_title">Safety Anti-Spyware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/14/cyber-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Cyber Security Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RESpyWare Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 20:46:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[RESpyWare]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=e17c585a-7919-4b7b-a4fa-f73eb96566da</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the RESpyWare adware. a-squared Anti-Malware detects this malware as Adware.Win32.RESpyWare.
RESpyWare, come from respyware.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of RESpyWare also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the RESpyWare adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">Adware.Win32.RESpyWare</a>.</p>
<p>RESpyWare, come from respyware.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of RESpyWare also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, RESpyWare will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\RESpyWare Software\RESpyWare\RESpyWare.exe</li>
<li>%ProgramFiles%\RESpyWare Software\RESpyWare\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\RESpyWare.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\RESpyWare\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\RESpyWare\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\RESpyWare\1 RESpyWare.lnk</li>
<li>%UserProfile%\Cookies\userdemo@respyware[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsk1A.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\RESpyWare</li>
<li>HKEY_LOCAL_MACHINE\software\RESpyWare</li>
<li>HKEY_CURRENT_USER\software\RESpyWare</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;RESpyWare.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_2.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_5.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.RESpyWare_10.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.RESpyWare?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/" rel="bookmark" class="crp_title">SecureKeeper Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/" rel="bookmark" class="crp_title">REAnti Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/keepcop-adware-removal-instructions/" rel="bookmark" class="crp_title">KeepCop Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>REAnti Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 17:16:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[REAnti]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=39e4f882-bf2c-42e2-9a71-2c69ff286de2</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the REAnti adware. a-squared Anti-Malware detects this malware as Adware.Win32.REAnti.
REAnti, come from reanti.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of REAnti also made TheDefend, GuardPcs, IGuardPc, SiteAdware, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the REAnti adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">Adware.Win32.REAnti</a>.</p>
<p>REAnti, come from reanti.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of REAnti also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, REAnti will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\REAnti Software\REAnti\REAnti.exe</li>
<li>%ProgramFiles%\REAnti Software\REAnti\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\REAnti.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\REAnti\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\REAnti\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\REAnti\1 REAnti.lnk</li>
<li>%UserProfile%\Cookies\userdemo@reanti[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsr3.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\REAnti</li>
<li>HKEY_LOCAL_MACHINE\software\REAnti</li>
<li>HKEY_CURRENT_USER\software\REAnti</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;REAnti.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_2.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_5.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_10.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.REAnti_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.REAnti?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/" rel="bookmark" class="crp_title">SecureKeeper Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/25/keepcop-adware-removal-instructions/" rel="bookmark" class="crp_title">KeepCop Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Additional Guard Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 18:52:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Additional Guard]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=91</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Additional Guard adware. a-squared Anti-Malware detects this malware as Adware.Win32.AdditionalGuard.
Additional Guard (hxxp://www.additional-guard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: Live PC Care, Enterprise Suite, System Defender, Windows Enterprise Defender, Windows PC [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Additional Guard adware. <a href="http://www.emsisoft.com/en/software/antimalware/" target="_blank">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdditionalGuard" target="_blank">Adware.Win32.AdditionalGuard</a>.</p>
<p>Additional Guard (hxxp://www.additional-guard.com) is a fraud application that shows false warning messages and misleading scan results. Come from the following family: <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LivePCCare" target="_blank">Live PC Care</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EnterpriseSuite" target="_blank">Enterprise Suite</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefender" target="_blank">System Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEnterpriseDefender">Windows Enterprise Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCDefender">Windows PC Defender</a>, etc. This adware create numerous junk files on your computer, usually at Recent folder, that are used to impersonate malware files. Once the program is running it will scan your computer and then display these files as infections, but will not allow you to remove them until you purchase the program.</p>
<p><strong>The main program will extract several files to (some name of the files and directory for this rogue are random):</strong></p>
<ul>
<li>%SystemRoot%\system32\drivers\etc\hosts</li>
<li> %AllUsersProfile%\Application Data\58969\WIf4c.exe</li>
<li> %AllUsersProfile%\Application Data\58969\WINAG.ico</li>
<li> %AllUsersProfile%\Application Data\WINAGSys\winag.cfg</li>
<li> %UserProfile%\Application Data\Additional Guard\cookies.sqlite</li>
<li> %UserProfile%\Application Data\Additional Guard\Instructions.ini</li>
<li> %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Additional Guard.lnk</li>
<li> %UserProfile%\Desktop\Additional Guard.lnk</li>
<li> %UserProfile%\Recent\grid.dll</li>
<li> %UserProfile%\Recent\PE.dll</li>
<li> %UserProfile%\Recent\PE.exe</li>
<li> %UserProfile%\Recent\sld.dll</li>
<li> %UserProfile%\Recent\ANTIGEN.drv</li>
<li> %UserProfile%\Recent\cid.sys</li>
<li> %UserProfile%\Recent\CLSV.dll</li>
<li> %UserProfile%\Recent\DBOLE.dll</li>
<li> %UserProfile%\Recent\DBOLE.drv</li>
<li> %UserProfile%\Recent\DBOLE.sys</li>
<li> %UserProfile%\Recent\eb.dll</li>
<li> %UserProfile%\Recent\eb.exe</li>
<li> %UserProfile%\Recent\eb.sys</li>
<li> %UserProfile%\Recent\eb.tmp</li>
<li> %UserProfile%\Recent\energy.drv</li>
<li> %UserProfile%\Recent\exec.drv</li>
<li> %UserProfile%\Start Menu\Additional Guard.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Additional Guard.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li> HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li> HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li> HKEY_LOCAL_MACHINE\software\Classes\Setup.DocHostUIHandler</li>
<li> HKEY_LOCAL_MACHINE\software\Classes\Setup.DocHostUIHandler\Clsid</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li> HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Additional Guard&#8221;</li>
</ul>
<p><strong>This rogue application also changes the hosts file:</strong></p>
<ul>
<li>127.0.0.1 localhost</li>
<li> 74.125.45.100 4-open-davinci.com</li>
<li> 74.125.45.100 securitysoftwarepayments.com</li>
<li> 74.125.45.100 privatesecuredpayments.com</li>
<li> 74.125.45.100 secure.privatesecuredpayments.com</li>
<li> 74.125.45.100 getantivirusplusnow.com</li>
<li> 74.125.45.100 secure-plus-payments.com</li>
<li> 74.125.45.100 www.getantivirusplusnow.com</li>
<li> 74.125.45.100 www.secure-plus-payments.com</li>
<li> 74.125.45.100 www.getavplusnow.com</li>
<li> 74.125.45.100 safebrowsing-cache.google.com</li>
<li> 74.125.45.100 www.securesoftwarebill.com</li>
<li> 74.125.45.100 secure.paysecuresystem.com</li>
<li> 74.125.45.100 paysoftbillsolution.com</li>
<li> 89.248.168.186 google.ae</li>
<li> 89.248.168.186 google.as</li>
<li> 89.248.168.186 google.at</li>
<li> 89.248.168.186 google.az</li>
<li> 89.248.168.186 google.ba</li>
<li> 89.248.168.186 google.be</li>
<li> 89.248.168.186 google.bg</li>
<li> 89.248.168.186 google.bs</li>
<li> 89.248.168.186 google.ca</li>
<li> 89.248.168.186 google.cd</li>
<li> 89.248.168.186 google.com.gh</li>
<li> 89.248.168.186 google.com.hk</li>
<li> 89.248.168.186 google.com.jm</li>
<li> 89.248.168.186 google.com.mx</li>
<li> 89.248.168.186 google.com.my</li>
<li> 89.248.168.186 google.com.na</li>
<li> 89.248.168.186 google.com.nf</li>
<li> 89.248.168.186 google.com.ng</li>
<li> 89.248.168.186 google.ch</li>
<li> 89.248.168.186 google.com.np</li>
<li> 89.248.168.186 google.com.pr</li>
<li> 89.248.168.186 google.com.qa</li>
<li> 89.248.168.186 google.com.sg</li>
<li> 89.248.168.186 google.com.tj</li>
<li> 89.248.168.186 google.com.tw</li>
<li> 89.248.168.186 google.dj</li>
<li> 89.248.168.186 google.de</li>
<li> 89.248.168.186 google.dk</li>
<li> 89.248.168.186 google.dm</li>
<li> 89.248.168.186 google.ee</li>
<li> 89.248.168.186 google.fi</li>
<li> 89.248.168.186 google.fm</li>
<li> 89.248.168.186 google.fr</li>
<li> 89.248.168.186 google.ge</li>
<li> 89.248.168.186 google.gg</li>
<li> 89.248.168.186 google.gm</li>
<li> 89.248.168.186 google.gr</li>
<li> 89.248.168.186 google.ht</li>
<li> 89.248.168.186 google.ie</li>
<li> 89.248.168.186 google.im</li>
<li> 89.248.168.186 google.in</li>
<li> 89.248.168.186 google.it</li>
<li> 89.248.168.186 google.ki</li>
<li> 89.248.168.186 google.la</li>
<li> 89.248.168.186 google.li</li>
<li> 89.248.168.186 google.lv</li>
<li> 89.248.168.186 google.ma</li>
<li> 89.248.168.186 google.ms</li>
<li> 89.248.168.186 google.mu</li>
<li> 89.248.168.186 google.mw</li>
<li> 89.248.168.186 google.nl</li>
<li> 89.248.168.186 google.no</li>
<li> 89.248.168.186 google.nr</li>
<li> 89.248.168.186 google.nu</li>
<li> 89.248.168.186 google.pl</li>
<li> 89.248.168.186 google.pn</li>
<li> 89.248.168.186 google.pt</li>
<li> 89.248.168.186 google.ro</li>
<li> 89.248.168.186 google.ru</li>
<li> 89.248.168.186 google.rw</li>
<li> 89.248.168.186 google.sc</li>
<li> 89.248.168.186 google.se</li>
<li> 89.248.168.186 google.sh</li>
<li> 89.248.168.186 google.si</li>
<li> 89.248.168.186 google.sm</li>
<li> 89.248.168.186 google.sn</li>
<li> 89.248.168.186 google.st</li>
<li> 89.248.168.186 google.tl</li>
<li> 89.248.168.186 google.tm</li>
<li> 89.248.168.186 google.tt</li>
<li> 89.248.168.186 google.us</li>
<li> 89.248.168.186 google.vu</li>
<li> 89.248.168.186 google.ws</li>
<li> 89.248.168.186 google.co.ck</li>
<li> 89.248.168.186 google.co.id</li>
<li> 89.248.168.186 google.co.il</li>
<li> 89.248.168.186 google.co.in</li>
<li> 89.248.168.186 google.co.jp</li>
<li> 89.248.168.186 google.co.kr</li>
<li> 89.248.168.186 google.co.ls</li>
<li> 89.248.168.186 google.co.ma</li>
<li> 89.248.168.186 google.co.nz</li>
<li> 89.248.168.186 google.co.tz</li>
<li> 89.248.168.186 google.co.ug</li>
<li> 89.248.168.186 google.co.uk</li>
<li> 89.248.168.186 google.co.za</li>
<li> 89.248.168.186 google.co.zm</li>
<li> 89.248.168.186 google.com</li>
<li> 89.248.168.186 google.com.af</li>
<li> 89.248.168.186 google.com.ag</li>
<li> 89.248.168.186 google.com.ar</li>
<li> 89.248.168.186 google.com.au</li>
<li> 89.248.168.186 google.com.bn</li>
<li> 89.248.168.186 google.com.br</li>
<li> 89.248.168.186 google.com.by</li>
<li> 89.248.168.186 google.com.bz</li>
<li> 89.248.168.186 google.com.cu</li>
<li> 89.248.168.186 google.com.ec</li>
<li> 89.248.168.186 google.com.fj</li>
<li> 89.248.168.186 www.google.ae</li>
<li> 89.248.168.186 www.google.as</li>
<li> 89.248.168.186 www.google.at</li>
<li> 89.248.168.186 www.google.az</li>
<li> 89.248.168.186 www.google.ba</li>
<li> 89.248.168.186 www.google.be</li>
<li> 89.248.168.186 www.google.bg</li>
<li> 89.248.168.186 www.google.bs</li>
<li> 89.248.168.186 www.google.ca</li>
<li> 89.248.168.186 www.google.cd</li>
<li> 89.248.168.186 www.google.com.gh</li>
<li> 89.248.168.186 www.google.com.hk</li>
<li> 89.248.168.186 www.google.com.jm</li>
<li> 89.248.168.186 www.google.com.mx</li>
<li> 89.248.168.186 www.google.com.my</li>
<li> 89.248.168.186 www.google.com.na</li>
<li> 89.248.168.186 www.google.com.nf</li>
<li> 89.248.168.186 www.google.com.ng</li>
<li> 89.248.168.186 www.google.ch</li>
<li> 89.248.168.186 www.google.com.np</li>
<li> 89.248.168.186 www.google.com.pr</li>
<li> 89.248.168.186 www.google.com.qa</li>
<li> 89.248.168.186 www.google.com.sg</li>
<li> 89.248.168.186 www.google.com.tj</li>
<li> 89.248.168.186 www.google.com.tw</li>
<li> 89.248.168.186 www.google.dj</li>
<li> 89.248.168.186 www.google.de</li>
<li> 89.248.168.186 www.google.dk</li>
<li> 89.248.168.186 www.google.dm</li>
<li> 89.248.168.186 www.google.ee</li>
<li> 89.248.168.186 www.google.fi</li>
<li> 89.248.168.186 www.google.fm</li>
<li> 89.248.168.186 www.google.fr</li>
<li> 89.248.168.186 www.google.ge</li>
<li> 89.248.168.186 www.google.gg</li>
<li> 89.248.168.186 www.google.gm</li>
<li> 89.248.168.186 www.google.gr</li>
<li> 89.248.168.186 www.google.ht</li>
<li> 89.248.168.186 www.google.ie</li>
<li> 89.248.168.186 www.google.im</li>
<li> 89.248.168.186 www.google.in</li>
<li> 89.248.168.186 www.google.it</li>
<li> 89.248.168.186 www.google.ki</li>
<li> 89.248.168.186 www.google.la</li>
<li> 89.248.168.186 www.google.li</li>
<li> 89.248.168.186 www.google.lv</li>
<li> 89.248.168.186 www.google.ma</li>
<li> 89.248.168.186 www.google.ms</li>
<li> 89.248.168.186 www.google.mu</li>
<li> 89.248.168.186 www.google.mw</li>
<li> 89.248.168.186 www.google.nl</li>
<li> 89.248.168.186 www.google.no</li>
<li> 89.248.168.186 www.google.nr</li>
<li> 89.248.168.186 www.google.nu</li>
<li> 89.248.168.186 www.google.pl</li>
<li> 89.248.168.186 www.google.pn</li>
<li> 89.248.168.186 www.google.pt</li>
<li> 89.248.168.186 www.google.ro</li>
<li> 89.248.168.186 www.google.ru</li>
<li> 89.248.168.186 www.google.rw</li>
<li> 89.248.168.186 www.google.sc</li>
<li> 89.248.168.186 www.google.se</li>
<li> 89.248.168.186 www.google.sh</li>
<li> 89.248.168.186 www.google.si</li>
<li> 89.248.168.186 www.google.sm</li>
<li> 89.248.168.186 www.google.sn</li>
<li> 89.248.168.186 www.google.st</li>
<li> 89.248.168.186 www.google.tl</li>
<li> 89.248.168.186 www.google.tm</li>
<li> 89.248.168.186 www.google.tt</li>
<li> 89.248.168.186 www.google.us</li>
<li> 89.248.168.186 www.google.vu</li>
<li> 89.248.168.186 www.google.ws</li>
<li> 89.248.168.186 www.google.co.ck</li>
<li> 89.248.168.186 www.google.co.id</li>
<li> 89.248.168.186 www.google.co.il</li>
<li> 89.248.168.186 www.google.co.in</li>
<li> 89.248.168.186 www.google.co.jp</li>
<li> 89.248.168.186 www.google.co.kr</li>
<li> 89.248.168.186 www.google.co.ls</li>
<li> 89.248.168.186 www.google.co.ma</li>
<li> 89.248.168.186 www.google.co.nz</li>
<li> 89.248.168.186 www.google.co.tz</li>
<li> 89.248.168.186 www.google.co.ug</li>
<li> 89.248.168.186 www.google.co.uk</li>
<li> 89.248.168.186 www.google.co.za</li>
<li> 89.248.168.186 www.google.co.zm</li>
<li> 89.248.168.186 www.google.com</li>
<li> 89.248.168.186 www.google.com.af</li>
<li> 89.248.168.186 www.google.com.ag</li>
<li> 89.248.168.186 www.google.com.ar</li>
<li> 89.248.168.186 www.google.com.au</li>
<li> 89.248.168.186 www.google.com.bn</li>
<li> 89.248.168.186 www.google.com.br</li>
<li> 89.248.168.186 www.google.com.by</li>
<li> 89.248.168.186 www.google.com.bz</li>
<li> 89.248.168.186 www.google.com.cu</li>
<li> 89.248.168.186 www.google.com.ec</li>
<li> 89.248.168.186 www.google.com.fj</li>
<li> 89.248.168.186 google.com</li>
<li> 89.248.168.186 www.google.com</li>
<li> 89.248.168.186 bing.com</li>
<li> 89.248.168.186 www.bing.com</li>
<li> 89.248.168.186 search.yahoo.com</li>
<li> 89.248.168.186 www.search.yahoo.com</li>
<li> 89.248.168.186 search.live.com</li>
<li>89.248.168.186 search.msn.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_1.png"><img class="alignnone" title="Adware.Win32.AdditionalGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_1.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_2.png"><img class="alignnone" title="Adware.Win32.AdditionalGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_2.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_3.png"><img class="alignnone" title="Adware.Win32.AdditionalGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_3.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_4.png"><img class="alignnone" title="Adware.Win32.AdditionalGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_4.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_5.png"><img class="alignnone" title="Adware.Win32.AdditionalGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.AdditionalGuard_5.png" alt="" width="400" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of Additional Guard </span></strong><strong><span style="font-size: small;">(Adware.Win32.</span></strong><strong><span style="font-size: small;">AdditionalGuard</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Live Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KeepCop Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/25/keepcop-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/25/keepcop-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 19:16:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[KeepCop]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=fb660882-1231-4636-ab2f-9012f1c768a8</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the KeepCop adware. a-squared Anti-Malware detects this malware as Adware.Win32.KeepCop.
KeepCop is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author KeepCop also made TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the KeepCop adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">Adware.Win32.KeepCop</a>.</p>
<p>KeepCop is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author KeepCop also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, KeepCop will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\KeepCop Software\KeepCop\KeepCop.exe</li>
<li>%ProgramFiles%\KeepCop Software\KeepCop\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\KeepCop.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\KeepCop\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\KeepCop\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\KeepCop\1 KeepCop.lnk</li>
<li>%UserProfile%\Cookies\userdemo@keepcop[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsk2.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\KeepCop</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\KeepCop</li>
<li>HKEY_CURRENT_USER\software\KeepCop</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;KeepCop&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_2.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_5.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.KeepCop_10.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.KeepCop?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/" rel="bookmark" class="crp_title">SecureKeeper Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/" rel="bookmark" class="crp_title">REAnti Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/25/keepcop-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Professional Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 19:15:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=2c6dd1c8-d23e-4448-94ce-6c623d631097</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Malware Professional adware. a-squared Anti-Malware detects this malware as Adware.Win32.MalwareProfessional.
Malware Professional is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Malware Professional adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.MalwareProfessional.</p>
<p>Malware Professional is a rogue scanner program. Once installed, this application will be immediately perform scan action without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Malware Professional\noadware4_021709.na</li>
<li>%ProgramFiles%\Malware Professional\nutilities.dll</li>
<li>%ProgramFiles%\Malware Professional\unins000.dat</li>
<li>%ProgramFiles%\Malware Professional\unins000.exe</li>
<li>%ProgramFiles%\Malware Professional\UninstlDll.dll</li>
<li>%ProgramFiles%\Malware Professional\Malware Professional.exe</li>
<li>%AllUsersProfile%\Start Menu\Programs\Malware Professional\Uninstall Malware Professional .lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Malware Professional\Malware Professional .lnk</li>
<li>%UserProfile%\Desktop\Malware Professional.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Malware Professional 5.0_is1</li>
<li>HKEY_CURRENT_USER\software\Malware Professional</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.MalwareProfessional_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.MalwareProfessional_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.MalwareProfessional_10.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.MalwareProfessional_11.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.MalwareProfessional?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/14/windows-enterprise-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Enterprise Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/10/safety-anti-spyware-adware-removal-instructions/" rel="bookmark" class="crp_title">Safety Anti-Spyware Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/09/internet-security-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecureKeeper Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 19:03:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SecureKeeper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=2139c167-2fd1-4025-b7c4-a734eaa712ea</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SecureKeeper adware. a-squared Anti-Malware detects this malware as Adware.Win32.SecureKeeper.
SecureKeeper is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author SecureKeeper also made TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SecureKeeper adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">Adware.Win32.SecureKeeper</a>.</p>
<p>SecureKeeper is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author SecureKeeper also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SecureKeeper will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SecureKeeper Software\SecureKeeper\SecureKeeper.exe</li>
<li>%ProgramFiles%\SecureKeeper Software\SecureKeeper\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\SecureKeeper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecureKeeper\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecureKeeper\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SecureKeeper\1 SecureKeeper.lnk</li>
<li>%UserProfile%\Cookies\user@securekeeper[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsk18.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SecureKeeper</li>
<li>HKEY_LOCAL_MACHINE\software\SecureKeeper</li>
<li>HKEY_CURRENT_USER\software\SecureKeeper</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SecureKeeper&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_2.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_5.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_11.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SecureKeeper_10.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.SecureKeeper?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/" rel="bookmark" class="crp_title">REAnti Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/09/systemfighter-adware-removal-instructions/" rel="bookmark" class="crp_title">SystemFighter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SiteVillain Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/17/sitevillain-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/17/sitevillain-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 19:28:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SiteVillain]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=26567eef-fe8c-4bac-aa6c-4d108417ab37</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SiteVillain adware. a-squared Anti-Malware detects this malware as Adware.Win32.SiteVillain.
SiteVillain is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author SiteVillain also made TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the SiteVillain adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteVillain" target="_blank">Adware.Win32.SiteVillain</a>.</p>
<p>SiteVillain is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author SiteVillain also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, SiteVillain will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SiteVillain Software\SiteVillain\SiteVillain.exe</li>
<li>%ProgramFiles%\SiteVillain Software\SiteVillain\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\SiteVillain.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteVillain\1 SiteVillain.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteVillain\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SiteVillain\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\virus demo@sitevillain[1].txt</li>
<li>%UserProfile%\Local Settings\Temp\nsh11.tmp\nsProcess.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SiteVillain</li>
<li>HKEY_LOCAL_MACHINE\software\SiteVillain</li>
<li>HKEY_CURRENT_USER\software\SiteVillain</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SiteVillain&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_1.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_2.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_5.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_10.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.SiteVillain_9.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.SiteVillain?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/" rel="bookmark" class="crp_title">SecureKeeper Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/" rel="bookmark" class="crp_title">REAnti Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/17/sitevillain-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 18:49:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Protector]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=33824476-6520-4624-806e-cac24e26bd43</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Personal Protector adware. a-squared Anti-Malware detects this malware as Adware.Win32.PersonalProtector.
Personal Protector is a rogue scanner program. Once you click the setup file, the application will be immediately installed and scan without prior notice. This fake scanner application tries to trick you by [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Personal Protector adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.PersonalProtector.</p>
<p>Personal Protector is a rogue scanner program. Once you click the setup file, the application will be immediately installed and scan without prior notice. This fake scanner application tries to trick you by displaying misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application. Be careful with this program, because it not going to protect your computer but will only spend your money. Additionally, on the computers that are already infected, Personal Protector will be running automatically when starting Windows.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Personal Protector\baseadd.wdb</li>
<li>%ProgramFiles%\Personal Protector\conf.wcf</li>
<li>%ProgramFiles%\Personal Protector\personalprotector.exe</li>
<li>%ProgramFiles%\Personal Protector\quarant.wdb</li>
<li>%ProgramFiles%\Personal Protector\queue.wdb</li>
<li>%ProgramFiles%\Personal Protector\un.exe</li>
<li>%ProgramFiles%\Personal Protector\base.wdb</li>
<li>%SystemRoot%\tempfile2.bat</li>
<li>%AllUsersProfile%\Microsoft PData\inetprovider.dll</li>
<li>%UserProfile%\Desktop\Personal Protector.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Personal Protector\Personal Protector.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Personal Protector\Uninstall.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Personal Protector</li>
<li>HKEY_LOCAL_MACHINE\software\Personal Protector</li>
<li>HKEY_LOCAL_MACHINE\software\Personal Protector\Soft</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;personalprotector&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\RunOnce, &#8220;suicide&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.PersonalProtector_1.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.PersonalProtector_2.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.PersonalProtector_3.png" alt="" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.PersonalProtector?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Your PC Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/24/malware-professional-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Professional Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/07/beblohurlzone-trojan-removal-instructions/" rel="bookmark" class="crp_title">Bebloh/URLZone Trojan Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/08/virus-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Virus Protector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LinkSafeness Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/17/linksafeness-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/17/linksafeness-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 18:33:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[LinkSafeness]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=ef423379-e1b8-4bec-8d62-5b4890b72f64</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the LinkSafeness adware. a-squared Anti-Malware detects this malware as Adware.Win32.LinkSafeness.
LinkSafeness is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author LinkSafeness also made TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the LinkSafeness adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">Adware.Win32.LinkSafeness</a>.</p>
<p>LinkSafeness is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author LinkSafeness also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TheDefend" target="_blank">TheDefend</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardPcs" target="_blank">GuardPcs</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.IGuardPc" target="_blank">IGuardPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SiteAdware" target="_blank">SiteAdware</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiTroy" target="_blank">AntiTroy</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiKeep" target="_blank">AntiKeep</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAdd</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RESpyWare" target="_blank">RESpyWare</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.REAnti" target="_blank">REAnti</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.KeepCop" target="_blank">KeepCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureKeeper" target="_blank">SecureKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LinkSafeness" target="_blank">LinkSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntiAdd" target="_blank">AntiAid</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFighter" target="_blank">SystemFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemVeteran" target="_blank">SystemVeteran</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockProtector">BlockProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockKeeper" target="_blank">BlockKeeper</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockScanner" target="_blank">BlockScanner</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlockWatcher">BlockWatcher</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftStrongHold" target="_blank">SoftStronghold</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ShieldSafeness" target="_blank">ShieldSafeness</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftVeteran" target="_blank">SoftVeteran</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftSoldier" target="_blank">SoftSoldier</a>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SoftCop" target="_blank">SoftCop</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustFighter" target="_blank">TrustFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TrustSoldier" target="_blank">TrustSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafeFighter" target="_blank">SafeFighter</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecureVeteran" target="_blank">SecureVeteran</a>, etc. To further convince victims, LinkSafeness will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\LinkSafeness Software\LinkSafeness\LinkSafeness.exe</li>
<li>%ProgramFiles%\LinkSafeness Software\LinkSafeness\uninstall.exe</li>
<li>%AllUsersProfile%\Desktop\LinkSafeness.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\LinkSafeness\1 LinkSafeness.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\LinkSafeness\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\LinkSafeness\3 Uninstall.lnk</li>
<li>%UserProfile%\Cookies\user@linksafeness[2].txt</li>
<li>%UserProfile%\Local Settings\Temp\t5bgc2co</li>
<li>%UserProfile%\Local Settings\Temp\t5bgc2co.exe</li>
<li>%UserProfile%\Local Settings\Temp\nscC.tmp\nsProcess.dll</li>
<li>%UserProfile%\Local Settings\Temp\nsqA.tmp\time.dll</li>
<li>%UserProfile%\Local Settings\Temp\nsr8.tmp\time.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\LinkSafeness</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\LinkSafeness</li>
<li>HKEY_CURRENT_USER\software\LinkSafeness</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;LinkSafeness&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_1.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_2.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_4.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_5.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_6.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.LinkSafeness_8.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.LinkSafeness?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/19/securekeeper-adware-removal-instructions/" rel="bookmark" class="crp_title">SecureKeeper Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/26/reanti-adware-removal-instructions/" rel="bookmark" class="crp_title">REAnti Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/03/blockscanner-adware-removal-instructions/" rel="bookmark" class="crp_title">BlockScanner Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/28/softstronghold-adware-removal-instructions/" rel="bookmark" class="crp_title">SoftStronghold Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/27/respyware-adware-removal-instructions/" rel="bookmark" class="crp_title">RESpyWare Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/17/linksafeness-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warning of the new Russian Connection: Million dollar hoax from the Kremlin!</title>
		<link>http://www.anti-malware-blog.com/2009/11/17/warning-of-the-new-russian-connection-million-dollar-hoax-from-the-kremlin/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/17/warning-of-the-new-russian-connection-million-dollar-hoax-from-the-kremlin/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 13:18:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=51515712-4a31-4544-9cc2-a1711f797fc6</guid>
		<description><![CDATA[Who doesn&#8217;t want to be a millionaire? The so-called &#8220;Nigeria Connection&#8221; takes advantage of such dreams and has been making good money for years with pumped-up emails. The security software development specialists Emsi Software are now warning of a new &#8220;Russian Connection&#8221;. The millions are now being promised from the Kremlin. 
What is the Nigeria [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Who doesn&#8217;t want to be a millionaire? The so-called &#8220;<a href="http://www.emsisoft.com/en/kb/articles/ticker090325/">Nigeria Connection</a>&#8221; takes advantage of such dreams and has been making good money for years with pumped-up emails. The security software development specialists Emsi Software are now warning of a new &#8220;Russian Connection&#8221;. The millions are now being promised from the Kremlin. </strong></p>
<h3>What is the Nigeria Connection?</h3>
<p>Since 1988, large numbers of emails have been sent over the whole world, mostly from Nigeria. The tone of these mails is always the same: Someone has &#8220;found&#8221; a few million dollars lying in an orphaned bank account and is looking for a partner willing to make their bank account available for transferring the money out of the country. The account holder is offered a commission of up to 10 percent for their help.</p>
<p>With several million dollars, this commission is naturally worth the effort. This temptation has resulted in many users falling for this trick offer. Anyone taking up this offer without considering the illegal money-laundering nature of the whole process will not become rich but rather cleaned out. The victims must always first front up with a few thousand dollars &#8211; for expenses, bribes, documents. In the end it is always the same &#8211; no money, just expenses.</p>
<p>Christian Mairoll, the General Manager of Emsi Software GmbH, says: &#8220;When an email offer sounds too good to be true, then it is definitely not true.&#8221;</p>
<h4>Emsi Software warns of the &#8220;Russian Connection&#8221;</h4>
<p>Same approach, different source. Emsi Software warns of the first mails from the newly established &#8220;Russian Connection&#8221;. The mails currently in circulation claim to come from Russia &#8211; directly from Moscow and Kremlin circles, where millions are in fact invested in oil, heavy industry and other raw materials.</p>
<p>Christian Mairoll says: &#8220;The Russians are not taking half measures. In the mails we have seen, up to 52 million Euros are to be smuggled out of the country. Anyone willing to allow their bank account to be used for this is promised a commission of 8 percent. Since a warning is always necessary, we therefore provide the following warning: This is a hoax and completely fraudulent. Anyone answering this type of mail is immediately asked for payment for non-existent expenses. Any and all such mails from the &#8220;Russian Connection&#8221; must be immediately deleted.&#8221;</p>
<h4>Example of a &#8220;Russian Connection&#8221; email</h4>
<p><em>Good Day,<br />I am Andrei Raz***hov, I have a business brief which might interest you on the instruction of a business tycoon in Moscow whose business interest spans crude oil refining, mining, construction, real estate and tourism.</em></p>
<p><em>Over the past years the policies of the Kremlin has not been favorable towards his business and more importantly towards his person who seem to have a different political view from that of the Kremlin. Without boring you with politics of Russia, I will go straight to the point to ask for your cooperation to discreetly re-profile funds worth 52.2 Million euro own by this business tycoon from its present location via a bank in eastern Europe to a new investment location.</em></p>
<p><em>You will be paid 8% for your &#8216;management consultancy fees&#8217;, if we are able to reach terms. If you are interested, please write back to my senior colleague Mr. Andrev Sl**vik at **** and provide your telephone number and private e-mail address and he will provide further details.</em></p>
<p><em>Write back, we wait for your response.<br />Regards,<br />Andrei Raz***hov</em></p>
<h4>A new hobby: Bother crooks</h4>
<p>There is not much you can do about such scams, because still many users believe these emails. Some creative minds in the Web, however, thought that if we can not stop this nonsense, then at least we can try to steal the fraudsters as much time as possible to ensure that they don&#8217;t spend too much time on other victims. There are some very entertaining projects such as <a href="http://www.419eater.com/" target="_blank">www.419eater.com</a> und <a href="http://www.thescambaiter.com/" target="_blank">www.thescambaiter.com</a> where you can find lots of funny stories and hall of shame picture galleries.</p>
<p>Article from <a href="http://www.emsisoft.com/en/kb/articles/ticker091112/" target="_blank">a-squared Knowledgebase</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/07/beblohurlzone-trojan-removal-instructions/" rel="bookmark" class="crp_title">Bebloh/URLZone Trojan Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/fakeantivir-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeAntivir Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/17/system-adware-scanner-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">System Adware Scanner 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/01/personal-security-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/28/antispyware-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Antispyware Shield Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/17/warning-of-the-new-russian-connection-million-dollar-hoax-from-the-kremlin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Suite Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/16/enterprise-suite-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/16/enterprise-suite-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 17:36:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Enterprise Suite]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=94</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Enterprise Suite adware. a-squared Anti-Malware detects this malware as Adware.Win32.EnterpriseSuite.
Enterprise Suite is a fraud application that shows false warning messages and misleading scan results. Come from the following family: Additional Guard, PC Live Guard, Live PC Care, Additional Guard, Enterprise Suite, System [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Enterprise Suite adware. <a href="http://www.emsisoft.com/en/software/antimalware/" target="_blank">a-squared Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EnterpriseSuite" target="_blank">Adware.Win32.EnterpriseSuite</a>.</p>
<p>Enterprise Suite is a fraud application that shows false warning messages and misleading scan results. Come from the following family: <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdditionalGuard">Additional Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCLiveGuard" target="_blank">PC Live Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LivePCCare" target="_blank">Live PC Care</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdditionalGuard" target="_blank">Additional Guard</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EnterpriseSuite" target="_blank">Enterprise Suite</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefender" target="_blank">System Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEnterpriseDefender">Windows Enterprise Defender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCDefender">Windows PC Defender</a>, etc. This adware create numerous junk files on your computer, usually at Recent folder, that are used to impersonate malware files. Once the program is running it will scan your computer and then display these files as infections, but will not allow you to remove them until you purchase the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\COMMAND.COM</li>
<li>%SystemRoot%\system32\DOSX.EXE</li>
<li>%SystemRoot%\system32\HIMEM.SYS</li>
<li>%SystemRoot%\system32\MSCDEXNT.EXE</li>
<li>%SystemRoot%\system32\REDIR.EXE</li>
<li>%SystemRoot%\system32\drivers\etc\hosts</li>
<li>%SystemRoot%\system32\WBEM\Logs\mofcomp.log</li>
<li>%SystemRoot%\system32\WBEM\Logs\wbemprox.log</li>
<li>%AllUsersProfile%\Application Data\58969\WEf4c.exe</li>
<li>%AllUsersProfile%\Application Data\58969\WES.ico</li>
<li>%AllUsersProfile%\Application Data\WESSys\wes.cfg</li>
<li>%UserProfile%\Application Data\Enterprise Suite\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Enterprise Suite\Instructions.ini</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Enterprise Suite.lnk</li>
<li>%UserProfile%\Desktop\322.mof</li>
<li>%UserProfile%\Desktop\Enterprise Suite.lnk</li>
<li>%UserProfile%\Desktop\mozcrt19.dll</li>
<li>%UserProfile%\Desktop\sqlite3.dll</li>
<li>%UserProfile%\Desktop\WESSys\vd952342.bd</li>
<li>%UserProfile%\Recent\ANTIGEN.tmp</li>
<li>%UserProfile%\Recent\cb.tmp</li>
<li>%UserProfile%\Recent\CLSV.dll</li>
<li>%UserProfile%\Recent\delfile.tmp</li>
<li>%UserProfile%\Recent\eb.dll</li>
<li>%UserProfile%\Recent\eb.drv</li>
<li>%UserProfile%\Recent\energy.tmp</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\gid.sys</li>
<li>%UserProfile%\Recent\hymt.tmp</li>
<li>%UserProfile%\Recent\pal.drv</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\PE.exe</li>
<li>%UserProfile%\Recent\PE.sys</li>
<li>%UserProfile%\Recent\PE.tmp</li>
<li>%UserProfile%\Recent\sld.exe</li>
<li>%UserProfile%\Recent\tjd.exe</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Start Menu\Enterprise Suite.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Enterprise Suite.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_487c8.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\xp_487c8.DocHostUIHandler\Clsid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Arrakis3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdreinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdsubwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdtkexec.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdwizreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9&#215;206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\launcher.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\livesrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\seccenter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\uiscan.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrepl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsserv.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Enterprise Suite&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_1.png"><img class="alignnone" title="Adware.Win32.EnterpriseSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_1.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_2.png"><img class="alignnone" title="Adware.Win32.EnterpriseSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_2.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_3.png"><img class="alignnone" title="Adware.Win32.EnterpriseSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_3.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_4.png"><img class="alignnone" title="Adware.Win32.EnterpriseSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_4.png" alt="" width="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_5.png"><img class="alignnone" title="Adware.Win32.EnterpriseSuite" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.EnterpriseSuite_5.png" alt="" width="400" /></a></p>
<p><strong><span style="font-size: small;">How to remove the infection of Enterprise Suite </span></strong><strong><span style="font-size: small;">(Adware.Win32.</span></strong><strong><span style="font-size: small;">EnterpriseSuite</span></strong><strong><span style="font-size: small;">)?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/16/system-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">System Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/16/enterprise-suite-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Control Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 17:57:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Center]]></category>
		<category><![CDATA[Control]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=4ae34c11-8a1f-41a9-b16e-dfef6d39637e</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak for the Control Center adware. a-squared Anti-Malware detect this malware as Adware.Win32.ControlCenter.
Control Center is a rogue application. It uses the misleading promotional methods to deceive their victims so willing to buy the program. When this application scan your computer, Control Center will shows you [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak for the Control Center adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detect this malware as Adware.Win32.ControlCenter.</p>
<p>Control Center is a rogue application. It uses the misleading promotional methods to deceive their victims so willing to buy the program. When this application scan your computer, Control Center will shows you misleading scan results, but you will not be able to remove them until you purchase this fake application. And also, once installed,  it will start automatically when starting Windows.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\CC\agent.exe</li>
<li>%UserProfile%\Application Data\CC\cc.exe</li>
<li>%UserProfile%\Application Data\CC\settings.ini</li>
<li>%UserProfile%\Application Data\CC\uninstall.exe</li>
<li>%UserProfile%\Application Data\CC\faq\guide.html</li>
<li>%UserProfile%\Application Data\CC\faq\images\05.png</li>
<li>%UserProfile%\Application Data\CC\faq\images\06.png</li>
<li>%UserProfile%\Application Data\CC\faq\images\07.png</li>
<li>%UserProfile%\Application Data\CC\faq\images\08.png</li>
<li>%UserProfile%\Application Data\CC\faq\images\09.png</li>
<li>%UserProfile%\Application Data\CC\faq\images\10.png</li>
<li>%UserProfile%\Desktop\Control center.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Control center</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;agent.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.ControlCenter_1.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.ControlCenter_2.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.ControlCenter_3.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/11/Adware.Win32.ControlCenter_4.png" alt="" width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.ControlCenter?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Components Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/14/windows-enterprise-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Enterprise Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/19/fakecopyright-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeCopyright Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
