Adware.Win32.Agent.rf manual removal:
Kill processes:
%ProgramFiles%\\KvmSecure\\KvmSecure.exe
Delete registry values:HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\CurrentVersion\Run\”KvmSecure.exe” = “43 00 3A 00 5C 00 50 00 72 00 6F 00 67 00 72 00 61 00 6D 00 20 00 46 00 69 00 6C 00 65 00 73 00 5C 00 4B 00 76 00 6D 00 53 00 65 00 63 00 75 00 72 00 65 00 5C 00 4B 00 76 00 6D 00 53 00 65 00 63 00 75 00 72 00 65 00 2E 00 65 00 78 00 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 5C 4B 76 6D 53 65 63 75 72 65 5C 4B 76 6D 53 65 63 75 72 65 2E 65 78 65 00 74 61 72 74 20 4D 65 6E 75 5C 50 72 6F 67 72 61 6D 73 5C 4B 76 6D 53 65 63 75 72 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 B2 1E 99 3F
HKEY_CURRENT_USER\Software\KvmSecure\”Autorun” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”TotalScans” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”Signatures” = “0″
HKEY_CURRENT_USER\Software\KvmSecure\”lastScanDate” = “130507D7″
HKEY_CURRENT_USER\Software\KvmSecure\”CheckForUpdates” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ScanProcesses” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ScanRegistry” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”BasesVersion” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”CoreVersion” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”QuickScanAtStartup” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”StartMinimized” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ID” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”lastScanTime” = “07040033″
HKEY_CURRENT_USER\Software\KvmSecure\”lastUpdateDate” = “0″
HKEY_CURRENT_USER\Software\KvmSecure\”lastUpdateTime” = “0″
HKEY_CURRENT_USER\Software\KvmSecure\”RegisterShellExtension” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ScanArchives” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ScanFiles” = “1″
HKEY_CURRENT_USER\Software\KvmSecure\”ScanMail” = “1″
Unregister DLLs:%ProgramFiles%\\KvmSecure\\zlib.dll
Delete files:%UserProfile%\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\KvmSecure.lnk %UserProfile%\\Desktop\\KvmSecure.lnk %ProgramFiles%\\KvmSecure\\vscan.tsi %UserProfile%\\Start Menu\\Programs\\KvmSecure\\KvmSecure.lnk
Post Comment:
Attention: Use this form only if you have additional information about Adware.Win32.Agent.rf parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.