Remove XP AntiMalware. Description and removal instructions

 
Title: XP AntiMalware
Also known as: XPAntiMalware
Type: Spyware
Severity scale:XP AntiMalware severity is 67  (67 / 100)
 
XP AntiMalware is a rogue anti-malware program that is promoted through the use of Trojans, browser hijackers and other similar malware. When your computer is infected with this bogus software, you will see many fake security alerts and notifications stating that your computer is infected. While running, XPAntiMalware will supposedly scan your computer and display a variety of infections that won't be removed unless you first purchase the program. The scan results are false, you can safely ignore them. The same could be said about fake system security alerts, you should ignore them too.

To make things even worse, XP AntiMalware will hijack Internet Explorer so that you will be constantly redirected to various misleading websites that promote malicious software or display misleading online ads. The rogue application will also block security related websites and antivirus software to protect itself form being deleted. As you can see, program is nothing more but a scam. Please use the removal guide below to remove XP AntiMalware from your PC as soon as possible.

XP AntiMalware removal instructions:

1. Click Start->Run (or WinKey+R). Input: "command". Press Enter or click OK.


2. Type "notepad" as shown in the image below and press Enter. Notepad will open.


3. Copy and past the following text into Notepad:


Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USERSoftwareClasses.exe]
[-HKEY_CURRENT_USERSoftwareClassessecfile]
[-HKEY_CLASSES_ROOTsecfile]
[-HKEY_CLASSES_ROOT.exeshellopencommand]

[HKEY_CLASSES_ROOTexefileshellopencommand]
@=""%1" %*"

[HKEY_CLASSES_ROOT.exe]
@="exefile"
"Content Type"="application/x-msdownload"

4. Save file as "exefix.reg" (without quotation-marks) to your Desktop.
NOTE: choose Save as type: All files


5. Double-click to open exefix.reg. Click "Yes" for Registry Editor prompt window.

6. Download Spyware Doctor or an automatic removal tool below. Update Spyware Doctor and run a full system scan.

If you can't complete the above steps then please use another PC to download an automatic removal tool and exefix.reg (Right Click (Save Target As)) to download file. Copy these files to USB flash drive or any other external media and transfer them to infected computer. Launch exefix.reg file first and then install Spyware Doctor.


Related files: %UserProfile%Local SettingsApplication Dataave.exe

XP AntiMalware properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Automatic XP AntiMalware removal:

remover for XP AntiMalware

XP AntiMalware manual removal:

Kill processes:
ave.exe
Delete registry values:
HKEY_CURRENT_USERSoftwareClasses.exe
HKEY_CURRENT_USERSoftwareClasses.exeDefaultIcon
HKEY_CURRENT_USERSoftwareClasses.exeshell
HKEY_CURRENT_USERSoftwareClasses.exeshellopen
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand
HKEY_CURRENT_USERSoftwareClasses.exeshellrunas
HKEY_CURRENT_USERSoftwareClasses.exeshellrunascommand
HKEY_CURRENT_USERSoftwareClasses.exeshellstart
HKEY_CURRENT_USERSoftwareClasses.exeshellstartcommand
HKEY_CURRENT_USERSoftwareClassessecfile
HKEY_CURRENT_USERSoftwareClassessecfileDefaultIcon
HKEY_CURRENT_USERSoftwareClassessecfileshell
HKEY_CURRENT_USERSoftwareClassessecfileshellopen
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand
HKEY_CURRENT_USERSoftwareClassessecfileshellrunas
HKEY_CURRENT_USERSoftwareClassessecfileshellrunascommand
HKEY_CURRENT_USERSoftwareClassessecfileshellstart
HKEY_CURRENT_USERSoftwareClassessecfileshellstartcommand
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand | @ = “”%AppData%ave.exe” /START “%1″ %*”
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand | IsolatedCommand = “”%1″ %*”
HKEY_CURRENT_USERSoftwareClasses.exe | @ = “secfile”
HKEY_CURRENT_USERSoftwareClasses.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand | @ = “”%AppData%ave.exe” /START “%1″ %*”
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand | IsolatedCommand = “”%1″ %*”
Delete files:
%UserProfile%\Local Settings\Application Data\ave.exe

Other programs to remove XP AntiMalware:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 17/03/10
Information updated: 28/04/10

Additional resources related to XP AntiMalware:

Attention: If you know or you have a website or page about XP AntiMalware removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about XP AntiMalware parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2010-04-16 16:04:18
FYI- we beat this virus once, or so we thought...it comes back as vma.exe At least the user knew enough this time not to think it was real and follow all the faux prompts. We are running NAV, superanti-spyware, SpyBot AND MalwareBytes...how many damn software do we need to get rid of this thing!

2. by . 2010-04-16 04:04:29
i did everything and the spyware doctor said it removed all the trojans and stuff, but why do i keep getting a popup from the anti malware?

3. by . 2010-03-20 06:03:13
la sequence n'est pas reconnue comme sequence de commande de registre...


Latest spyware news:
Similar parasites: