Title: Xema
Type:

Remove Xema. Removal instructions


 
Severity scale:Xema severity is 47  (47 / 100)
 
Xema is a worm that spreads through removable media. The parasite also searches for executables and infects them. It is very dangerous malware as it can download and install additional computer parasites.

Xema modifies system files and registry enters and enables itself this way to run on boot. Its first action is spreading further by use of USB thumbdrives. But the main purpose of Xema trojan is stealing various information about infected machine and sending the gathered data to a remote attacker. Xema functions secretly and it’s difficult to remove. It’s necessary to delete Xema because it puts privacy and security at risk.

Related files: autorun.inf, ~WR00002.doc, ~WR00001.doc, ~INFO2, deskinf.ini, .iau, software.chk, systemevent.log, w1234.exe, c_20462.nls, c_19460.nls, c_10810.nls, msregsv.exe, serlibk.exe, shlmon.exe, windfire.exe, windfire2.exe, inter32.dll, shell64.dll, deskinf.pif

Xema properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Xema removal:

SpyHunter is recommended remover to uninstall Xema. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove Xema using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing Xema (2008-10-22 08:20:08)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing Xema (2008-10-22 08:20:08)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing Xema (2008-10-22 08:20:08)
XoftSpySE Anti Spyware

Xema manual removal:

Kill processes:
windfire2.exe w1234.exe serlibk.exe windfire.exe msregsv.exe
Delete registry values:
HKEY_CLASSES_ROOT\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}
Unregister DLLs:
inter32.dll shell64.dll

Delete files:
c_10810.nls c_19460.nls c_20462.nls inter32.dll shell64.dll shlmon.exe w1234.exe serlibk.exe windfire.exe windfire2.exe msregsv.exe config\\systemevent.log config\\software.chk config\\Temporary Internet Files\\.iau \\Recycled\\deskinf.pif \\Recycled\\deskinf.ini \\Recycled\\~INFO2 \\Recycled\\~WR00001.doc \\Recycled\\~WR00002.doc \\Recycled\\windfire2.exe \\autorun.inf
Information added: 2007-06-13 11:11:36
Information updated: 2008-10-22 05:42:53

Additional resources related to Xema:

Attention: If you know or you have a website or page about Xema removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about Xema parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Latest spyware news:
Subscribe to news

Similar parasites:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove Xema using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other