Remove Kernel32.exe. Description and removal instructions

 
Title: Kernel32.exe

Type: Adware
Severity scale:Kernel32.exe severity is 33  (33 / 100)
 
Kernel32.exe is a fake threat generated by rogue anti-spyware application called Ultra Antivir2009. Fake security alert states that user's computer is infected with trojan virus named kernel32.exe. The full notification reads:

"Warning!Trojan Found!
Threat detected: Trojan
File name: kernel32.exe
Threat name: Trojan-PSW.Win32.Hooker
File at risk of infection: C:\Documents and Settings\…
Total Vulnerabilities: 2
Description: This is a password-stealing Trojan. When activated, it installs itself to the system, copies itself to the Windows or Windows system directory and registers itself in the system registry auto-run section."

If the user decides to click "Remove All" infections button, he will automatically download and install Ultra Antivir2009 onto his computer. And this is the worse case, because Ultra Antivir2009 may seriously compromise system security. That's why we strongly recommend users to ignore fake Kernel32.exe threat and remove pop-up window that displays this disinformation as soon as possible.


Related files: vd952342.bd, ppal.tmp, snl2w.drv, ANTIGEN.sys, delfile.sys, kernel32.tmp, std.drv, Instructions.ini, Ultra Antivir2009.lnk, uavir.cfg

Kernel32.exe properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Kernel32.exe snapshot:
Kernel32.exe removal

Automatic Kernel32.exe removal:

remover for Kernel32.exe

Kernel32.exe manual removal:

Kill processes:
energy.exe SICKBOY.exe tjd.exe UA2009.exe
Delete registry values:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}
HKEY_CLASSES_ROOT\UA2009.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “4800156103″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Ultra Antivir2009″
Delete files:
uavir.cfg Ultra Antivir2009.lnk Instructions.ini std.drv kernel32.tmp delfile.sys ANTIGEN.sys snl2w.drv ppal.tmp snl2w.drv vd952342.bd
Delete directories:
c:\Documents and Settings\All Users\Application Data\7c69f0c
%UserProfile%\Application Data\Ultra Antivir2009
c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemStore
c:\Documents and Settings\All Users\Application Data\SystemStore

Other programs to remove Kernel32.exe:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 31/03/09
Information updated: 31/03/09

Additional resources related to Kernel32.exe:

Attention: If you know or you have a website or page about Kernel32.exe removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Kernel32.exe parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: