Remove Affilred. Description and removal instructions

 
Title: Affilred
Also known as: WinSecure
Type: Browser Hijackers
Severity scale:Affilred severity is 50  (50 / 100)
 
Affilred is a browser hijacker that blocks access to numerous web sites and redirects a web browser to predefined Internet resources without asking for user permission. Affilred must be manually installed. The parasite automatically runs on every Windows startup. Affilred creates lots of files in different locations, so it is quite difficult to get rid of.


Related files: axe.exe, cab.exe, criticalupdate.exe, highspeed-cable.exe, iprotect.exe, mshotfix.exe, MSupdate.exe, security32.exe, twain_32.exe, usbwin32.exe, winsecure.exe, comnt32.dll, inetconnect.dll, default.scr, memorymanager.pif, regisry.pif

Affilred properties:
• Changes browser settings
• Hides from the user
• Stays resident in background

Automatic Affilred removal:

remover for Affilred

Affilred manual removal:

Kill processes:
axe.exe, cab.exe, criticalupdate.exe, highspeed-cable.exe, iprotect.exe, mshotfix.exe, msupdate.exe, security32.exe, twain_32.exe, usbwin32.exe, winsecure.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Cab Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Security Hot Fix Update
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\RegistryMonitor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Security Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Security Update
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\WinTask
HKEY_LOCAL_MACHINE\SOFTWARE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe, %Windir%\iprotect.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load\Memory Manager
HKEY_CLASSES_ROOT\CLSID\{1BB87441-6B7F-4B60-885C-B7AF9F9AFDE3}
HKEY_CLASSES_ROOT\CLSID\{FD3A6AB4-5527-4B52-90AF-F90CD3270861}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1BB87441-6B7F-4B60-885C-B7AF9F9AFDE3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0CDAAEC2-E245-44CC-8357-CAB70172D017}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{77566C2A-2987-44BC-AC81-A02D19EE271B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8E668361-C801-41B7-BF89-2FC2C8DE9167}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C0DADD7E-D3F1-430D-B735-39DC6033592C}
Delete files:
axe.exe, cab.exe, criticalupdate.exe, highspeed-cable.exe, iprotect.exe, mshotfix.exe, msupdate.exe, security32.exe, twain_32.exe, usbwin32.exe, winsecure.exe, comnt32.dll, inetconnect.dll, default.scr, memorymanager.pif, regisry.pif
Misc:
Affilred may create all listed objects or install only few of them.

Exact file location:
cab.exe, criticalupdate.exe, winsecure.exe - C:
mshotfix.exe, msupdate.exe, twain_32.exe - C:\Windows or C:\Winnt
axe.exe, iprotect.exe, security32.exe, comnt32.dll, inetconnect.dll, memorymanager.pif - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Affilred:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 27/08/05
Information updated: 21/01/08

Additional resources related to Affilred:

Attention: If you know or you have a website or page about Affilred removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Affilred parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites:
Related articles: