XP Smart Security 2010 manual removal:
Kill processes:
av.exe ave.exe
Delete registry values:HKEY_CURRENT_USERSoftwareClasses.exe
HKEY_CURRENT_USERSoftwareClasses.exeDefaultIcon
HKEY_CURRENT_USERSoftwareClasses.exeshell
HKEY_CURRENT_USERSoftwareClasses.exeshellopen
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand
HKEY_CURRENT_USERSoftwareClasses.exeshellrunas
HKEY_CURRENT_USERSoftwareClasses.exeshellrunascommand
HKEY_CURRENT_USERSoftwareClasses.exeshellstart
HKEY_CURRENT_USERSoftwareClasses.exeshellstartcommand
HKEY_CURRENT_USERSoftwareClassessecfile
HKEY_CURRENT_USERSoftwareClassessecfileDefaultIcon
HKEY_CURRENT_USERSoftwareClassessecfileshell
HKEY_CURRENT_USERSoftwareClassessecfileshellopen
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand
HKEY_CURRENT_USERSoftwareClassessecfileshellrunas
HKEY_CURRENT_USERSoftwareClassessecfileshellrunascommand
HKEY_CURRENT_USERSoftwareClassessecfileshellstart
HKEY_CURRENT_USERSoftwareClassessecfileshellstartcommand
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand | @ = “”%AppData%av.exe” /START “%1″ %*”
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand | IsolatedCommand = “”%1″ %*”
HKEY_CURRENT_USERSoftwareClasses.exe | @ = “secfile”
HKEY_CURRENT_USERSoftwareClasses.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand | @ = “”%AppData%av.exe” /START “%1″ %*”
HKEY_CURRENT_USERSoftwareClassessecfileshellopencommand | IsolatedCommand = “”%1″ %*”
Delete files:%UserProfile%\Local Settings\Application Data\av.exe %UserProfile%\Local Settings\Application Data\ave.exe %UserProfile%\Local Settings\Application Data\WRblt8464P
Post Comment:
Attention: Use this form only if you have additional information about XP Smart Security 2010 parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Comments from visitors:
1. by .. 2010-04-22 13:04:59
goto file find VMA.exe from the root ot the registry hive and deleted all instances of the file
clicked F3 to find next and rebooted all worked fine
thanks for the tip
Can anybody help?
Or failing that any of their close relatives ?