Wednesday, October 31, 2012

Remove Win 8 Home Security 2013Remove Win 8 Home Security 2013

Remove Win 8 Home Security 2013
Win 8 Home Security 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Win 8 Home Security 2013 is installed. Win 8 Home Security 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Win 8 Home Security 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Win 8 Home Security 2013 is to urge the user to register Win 8 Home Security 2013 by purchasing the full version of Win 8 Home Security 2013 so that to earn some money from the user. Win 8 Home Security 2013 cannot detect and remove any malware / virus / trojan.


Win 8 Home Security 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Win 8 Home Security 2013 shown in the removal guide below. All files related to Win 8 Home Security 2013 must be deleted. 

Win 8 Home Security 2013 should be removed immediately!

Win 8 Home Security 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[various-file-names].exe

Delete Registry

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe


Remove Folders and Files
[Download Path]\[various-file-names].exe
Tuesday, October 30, 2012

Remove Win 8 Antispyware 2013Remove Win 8 Antispyware 2013

Remove Win 8 Antispyware 2013
Win 8 Antispyware 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Win 8 Antispyware 2013 is installed. Win 8 Antispyware 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Win 8 Antispyware 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Win 8 Antispyware 2013 is to urge the user to register Win 8 Antispyware 2013 by purchasing the full version of Win 8 Antispyware 2013 so that to earn some money from the user. Win 8 Antispyware 2013 cannot detect and remove any malware / virus / trojan.


Win 8 Antispyware 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Win 8 Antispyware 2013 shown in the removal guide below. All files related to Win 8 Antispyware 2013 must be deleted. 

Win 8 Antispyware 2013 should be removed immediately!

Win 8 Antispyware 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[various-file-names].exe

Delete Registry

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe


Remove Folders and Files
[Download Path]\[various-file-names].exe

Remove Win 8 Antivirus 2013Remove Win 8 Antivirus 2013

Remove Win 8 Antivirus 2013
Win 8 Antivirus 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Win 8 Antivirus 2013 is installed. Win 8 Antivirus 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Win 8 Antivirus 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Win 8 Antivirus 2013 is to urge the user to register Win 8 Antivirus 2013 by purchasing the full version of Win 8 Antivirus 2013 so that to earn some money from the user. Win 8 Antivirus 2013 cannot detect and remove any malware / virus / trojan.


Win 8 Antivirus 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Win 8 Antivirus 2013 shown in the removal guide below. All files related to Win 8 Antivirus 2013 must be deleted. 

Win 8 Antivirus 2013 should be removed immediately!

Win 8 Antivirus 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[various-file-names].exe

Delete Registry

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe


Remove Folders and Files
[Download Path]\[various-file-names].exe

Remove Win 8 Security Suite 2013Remove Win 8 Security Suite 2013

Remove Win 8 Security Suite 2013
Win 8 Security Suite 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Win 8 Security Suite 2013 is installed. Win 8 Security Suite 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Win 8 Security Suite 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Win 8 Security Suite 2013 is to urge the user to register Win 8 Security Suite 2013 by purchasing the full version of Win 8 Security Suite 2013 so that to earn some money from the user. Win 8 Security Suite 2013 cannot detect and remove any malware / virus / trojan.


Win 8 Security Suite 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Win 8 Security Suite 2013 shown in the removal guide below. All files related to Win 8 Security Suite 2013 must be deleted. 

Win 8 Security Suite 2013 should be removed immediately!

Win 8 Security Suite 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[various-file-names].exe

Delete Registry

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe


Remove Folders and Files
[Download Path]\[various-file-names].exe

Remove Micorsoft Essential Security Pro 2013Remove Micorsoft Essential Security Pro 2013

Remove Micorsoft Essential Security Pro 2013
Micorsoft Essential Security Pro 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Micorsoft Essential Security Pro 2013 is installed. Micorsoft Essential Security Pro 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Micorsoft Essential Security Pro 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Micorsoft Essential Security Pro 2013 is to urge the user to register Micorsoft Essential Security Pro 2013 by purchasing the full version of Micorsoft Essential Security Pro 2013 so that to earn some money from the user. Micorsoft Essential Security Pro 2013 cannot detect and remove any malware / virus / trojan.


Micorsoft Essential Security Pro 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Micorsoft Essential Security Pro 2013 shown in the removal guide below. All files related to Micorsoft Essential Security Pro 2013 must be deleted. 

Micorsoft Essential Security Pro 2013 should be removed immediately!

Micorsoft Essential Security Pro 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[various-file-names].exe

Delete Registry

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "[Download Path]\[various-file-names].exe" -a "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsSecurity" = "[Download Path]\[various-file-names].exe" -a "%1" %*.exe


Remove Folders and Files
[Download Path]\[various-file-names].exe
Friday, October 26, 2012

Remove Vista Total Security 2013Remove Vista Total Security 2013

Remove Vista Total Security 2013
Vista Total Security 2013 is a fake antivirus program created to urge the user to buy the full version of Vista Total Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Vista Total Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Vista Total Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Vista Total Security 2013 is nothing more than a scam and plagiarized antispyware program

Vista Total Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Vista Total Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Vista Total Security 2013. Finally, all the file related to Vista Total Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Vista Total Security 2013 should be removed immediately!
Vista Total Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Thursday, October 25, 2012

Remove Win 7 Total Security 2013Remove Win 7 Total Security 2013

Remove Win 7 Total Security 2013
Win 7 Total Security 2013 is a fake antivirus program created to urge the user to buy the full version of Win 7 Total Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 7 Total Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 7 Total Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 7 Total Security 2013 is nothing more than a scam and plagiarized antispyware program

Win 7 Total Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 7 Total Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 7 Total Security 2013. Finally, all the file related to Win 7 Total Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 7 Total Security 2013 should be removed immediately!
Win 7 Total Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit" = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)" = '"%LocalAppData%\kdn.exe" -a “C:\Program Files\Internet Explorer\iexplore.exe"'

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Friday, October 19, 2012

Remove File RestoreRemove File Restore

Remove File Restore
File Restore is fake hard drive diagnostic program which will definitely show pop ups to tell the user that the hard drive of the computer perform badly. File Restore CANNOT detect and remove any kind of hard drive problem. File Restore can only cheat the user to purchase the full version of File Restore so that to removed the detected problems. Do not believe any pop ups or report shown by File Restore. All of them is a lie.

File Restore can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by File Restore must be cleared by using Windows Registry Editor.

File Restore, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple problems on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of File Restore. After doing so, users will later find out that File Restore is incapable of ridding their system of any type of problem and will continually bombard them with deceptive pop-up messages. The only thing to do with File Restore is remove either manually or by using an updated spyware detection tool. It show an overview of the hard drive status. Do not believe the overview.

File Restore should be removed immediately!


File Restore Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe

Delete Registry

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = "Yes"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'


Remove Folders and Files

%CommonAppData%\[random]
%CommonAppData%\[random].exe
%CommonAppData%\[random]
%CommonAppData%\-[random]
%StartMenu%\Programs\File Restore
%Temp%\smtmp
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Restore.lnk
%UserProfile%\Desktop\File Restore.lnk

Tuesday, October 16, 2012

Remove Win 7 Security 2013Remove Win 7 Security 2013

Remove Win 7 Security 2013
Win 7 Security 2013 is a fake antivirus program created to urge the user to buy the full version of Win 7 Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 7 Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 7 Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 7 Security 2013 is nothing more than a scam and plagiarized antispyware program

Win 7 Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 7 Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 7 Security 2013. Finally, all the file related to Win 7 Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 7 Security 2013 should be removed immediately!
Win 7 Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit" = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)" = '"%LocalAppData%\kdn.exe" -a “C:\Program Files\Internet Explorer\iexplore.exe"'

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Thursday, October 11, 2012

Remove Windows Antipiracy VirusRemove Windows Antipiracy Virus

Remove Windows Antipiracy Virus
Windows Antipiracy Virus is a fake antivirus program which intend to urge the user whose computer is infected by Windows Antipiracy Virus to purchase the full version of Windows Antipiracy Virus. Windows Antipiracy Virus produces fake alert in order to cheat the user. Windows Antipiracy Virus installs into the computer without the confirmation of the user and configure itself to start automatically when windows boot. Windows Antipiracy Virus will then scan the computer and state that there are many malware in the computer and ask the user to purchase full version of Windows Antipiracy Virus to remove all the malwares.

Windows Antipiracy Virus provide fake features such as firewall, automatic update, antivirus protection, anti-phishing, advanced process control, autorun manager, service manager, all-in-one suite, quick scan, deep scan and custom scan. All of them cannot protect the computer from any kind of malware.

Windows Antipiracy Virus can be removed by stopping its processes [random].exe and Windows Antipiracy Virus.exe and the user should remember to kill the file. The registry settings should be restored by following the removal guide below.

Windows Antipiracy Virus should be removed immediately!

Windows Antipiracy Virus Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = 2012-2-28_1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe
... and many more Image File Execution Options entries.

Remove Folders ad Files
%AppData%\NPSWF32.dll
%AppData%\Protector-.exe
%AppData%\result.db
%CommonStartMenu%\Programs\Windows Antipiracy Virus.lnk
%Desktop%\Windows Antipiracy Virus .lnk

Remove XP Internet Security 2013Remove XP Internet Security 2013

Remove XP Internet Security 2013
XP Internet Security 2013 is a fake antivirus program created to urge the user to buy the full version of XP Internet Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! XP Internet Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. XP Internet Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. XP Internet Security 2013 is nothing more than a scam and plagiarized antispyware program

XP Internet Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

XP Internet Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by XP Internet Security 2013. Finally, all the file related to XP Internet Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

XP Internet Security 2013 should be removed immediately!
XP Internet Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Monday, October 8, 2012

Remove XP Antispyware 2013Remove XP Antispyware 2013

Remove XP Antispyware 2013
XP Antispyware 2013 is a fake antivirus program created to urge the user to buy the full version of XP Antispyware 2013 in order to earn some profit. Don't ever buy it as it is a cheat! XP Antispyware 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. XP Antispyware 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. XP Antispyware 2013 is nothing more than a scam and plagiarized antispyware program

XP Antispyware 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

XP Antispyware 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by XP Antispyware 2013. Finally, all the file related to XP Antispyware 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

XP Antispyware 2013 should be removed immediately!
XP Antispyware 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove Win 7 Home Security 2013Remove Win 7 Home Security 2013

Remove Win 7 Home Security 2013
Win 7 Home Security 2013 is a fake antivirus program created to urge the user to buy the full version of Win 7 Home Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 7 Home Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 7 Home Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 7 Home Security 2013 is nothing more than a scam and plagiarized antispyware program

Win 7 Home Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 7 Home Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 7 Home Security 2013. Finally, all the file related to Win 7 Home Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 7 Home Security 2013 should be removed immediately!
Win 7 Home Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove XP Security 2013Remove XP Security 2013

Remove XP Security 2013
XP Security 2013 is a fake antivirus program created to urge the user to buy the full version of XP Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! XP Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. XP Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. XP Security 2013 is nothing more than a scam and plagiarized antispyware program

XP Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

XP Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by XP Security 2013. Finally, all the file related to XP Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

XP Security 2013 should be removed immediately!
XP Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Sunday, October 7, 2012

Remove Vista Security 2013Remove Vista Security 2013

Remove Vista Security 2013
Vista Security 2013 is a fake antivirus program created to urge the user to buy the full version of Vista Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Vista Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Vista Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Vista Security 2013 is nothing more than a scam and plagiarized antispyware program

Vista Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Vista Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Vista Security 2013. Finally, all the file related to Vista Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Vista Security 2013 should be removed immediately!
Vista Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Saturday, October 6, 2012

Remove Vista Antispyware 2013Remove Vista Antispyware 2013

Remove Vista Antispyware 2013
Vista Antispyware 2013 is a fake antivirus program created to urge the user to buy the full version of Vista Antispyware 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Vista Antispyware 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Vista Antispyware 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Vista Antispyware 2013 is nothing more than a scam and plagiarized antispyware program

Vista Antispyware 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Vista Antispyware 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Vista Antispyware 2013. Finally, all the file related to Vista Antispyware 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Vista Antispyware 2013 should be removed immediately!
Vista Antispyware 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Wednesday, October 3, 2012

Remove Win 8 Defender 2013Remove Win 8 Defender 2013

Remove Win 8 Defender 2013
Win 8 Defender 2013 is a fake antivirus program created to urge the user to buy the full version of Win 8 Defender 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 8 Defender 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 8 Defender 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 8 Defender 2013 is nothing more than a scam and plagiarized antispyware program

Win 8 Defender 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 8 Defender 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 8 Defender 2013. Finally, all the file related to Win 8 Defender 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 8 Defender 2013 should be removed immediately!
Win 8 Defender 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Tuesday, October 2, 2012

Remove XP Home Security 2013Remove XP Home Security 2013

Remove XP Home Security 2013
XP Home Security 2013 is a fake antivirus program created to urge the user to buy the full version of XP Home Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! XP Home Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. XP Home Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. XP Home Security 2013 is nothing more than a scam and plagiarized antispyware program

XP Home Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

XP Home Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by XP Home Security 2013. Finally, all the file related to XP Home Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

XP Home Security 2013 should be removed immediately!
XP Home Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove Win 7 Antispyware 2013Remove Win 7 Antispyware 2013

Remove Win 7 Antispyware 2013
Win 7 Antispyware 2013 is a fake antivirus program created to urge the user to buy the full version of Win 7 Antispyware 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 7 Antispyware 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 7 Antispyware 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 7 Antispyware 2013 is nothing more than a scam and plagiarized antispyware program

Win 7 Antispyware 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 7 Antispyware 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 7 Antispyware 2013. Finally, all the file related to Win 7 Antispyware 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 7 Antispyware 2013 should be removed immediately!
Win 7 Antispyware 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove Win 7 Internet Security 2013Remove Win 7 Internet Security 2013

Remove Win 7 Internet Security 2013
Win 7 Internet Security 2013 is a fake antivirus program created to urge the user to buy the full version of Win 7 Internet Security 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Win 7 Internet Security 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Win 7 Internet Security 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Win 7 Internet Security 2013 is nothing more than a scam and plagiarized antispyware program

Win 7 Internet Security 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Win 7 Internet Security 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Win 7 Internet Security 2013. Finally, all the file related to Win 7 Internet Security 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Win 7 Internet Security 2013 should be removed immediately!
Win 7 Internet Security 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove Vista Defender 2013Remove Vista Defender 2013

Remove Vista Defender 2013
Vista Defender 2013 is a fake antivirus program created to urge the user to buy the full version of Vista Defender 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Vista Defender 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Vista Defender 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Vista Defender 2013 is nothing more than a scam and plagiarized antispyware program

Vista Defender 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Vista Defender 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Vista Defender 2013. Finally, all the file related to Vista Defender 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Vista Defender 2013 should be removed immediately!
Vista Defender 2013 Removal Guide
Kill Process
[random].exe

Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]


Remove Windows 7 Defender 2013Remove Windows 7 Defender 2013

Remove Windows 7 Defender 2013
Windows 7 Defender 2013 is a fake antivirus program created to urge the user to buy the full version of Windows 7 Defender 2013 in order to earn some profit. Don't ever buy it as it is a cheat! Windows 7 Defender 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. Windows 7 Defender 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Windows 7 Defender 2013 is nothing more than a scam and plagiarized antispyware program

Windows 7 Defender 2013 Vista Defender 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.

Windows 7 Defender 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Windows 7 Defender 2013. Finally, all the file related to Windows 7 Defender 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

Windows 7 Defender 2013 should be removed immediately!
Windows 7 Defender 2013 Removal Guide
Kill Process
[random].exe


Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]



Monday, October 1, 2012

Remove XP Defender 2013Remove XP Defender 2013

Remove XP Defender 2013
XP Defender 2013 is a fake antivirus program created to urge the user to buy the full version of XP Defender 2013 in order to earn some profit. Don't ever buy it as it is a cheat! XP Defender 2013 install itself into the computer without confirmation of the users and it start automatically when the windows boot. XP Defender 2013 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. XP Defender 2013 is nothing more than a scam and plagiarized antispyware program

XP Defender 2013 provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Configuration, Complete PC Protection,  Automating Updating, Protection against bank account fraud, Self-protection from malware, Update Now, Scan Now etc. All of them cannot protect the computer from any kind of malware.


XP Defender 2013 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by XP Defender 2013. Finally, all the file related to XP Defender 2013 must be deleted from the hard drive. All of them has been shown in the removal guide below.

XP Defender 2013 should be removed immediately!
XP Defender 2013 Removal Guide
Kill Process
[random].exe


Delete Registry
KEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random] "(Default)" = "Application"
HKEY_CURRENT_USER\Software\Classes\[random] "Content Type" = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\[random]\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "(Default)" = ""%LocalAppData%\[random].exe" -a "%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\open\command "IsolatedCommand" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "(Default)" = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\[random]\shell\runas\command "IsolatedCommand" = ""%1" %*"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%LocalAppData%\[random].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"

Remove Folders and Files
%CommonAppData%\[random]
%LocalAppData%\[random]
%LocalAppData%\[random].exe
%Temp%\[random]
%UserProfile%\Templates\[random]