XP Antivirus 2008 Removal and recovery of the final tab Desktop and Screen Saver

This item was filled under [ Computer Help ]

This is a serious virus, made with all the subtleties of the case.

Unregistered dll allocated from the command prompt:

* Regsvr32 / u Shlwapi.dll
* Regsvr32 / u wininet.dll

Through the task manager stop the processes:

* XPAntivirus.exe
* XPAntivirusUpdate.exe
* Xpa.exe
* Xpa2008.exe

Possibly delete the files on the disk:

* Xpa.exe
* Xpa2008.exe
* XPAntivirus.exe
* XPAntivirusUpdate.exe
* Shlwapi.dll
* Wininet.dll
* XP antivirus antivirusXP
* XPAntivirus.lnk
* Uninstall XPAntivirus.lnk
* Uninstall XPAntivirus.lnk
* XPAntivirus on the Web.lnk
* XPAntivirus on Web.lnk
* XPAntivirus.url
* Antivirus XP 2008.lnk
* Antivirus XP 2008.lnk
* Uninstall XP Antivirus 2008.lnk
* Uninstall XP Antivirus 2008.lnk

Through the system registry, regedit, and delete all references to the files above using Search and delete the key HKEY_USERS \ Software \ XP antivirus

For all those who have gone the Desktop tab and the screen saver display properties in Annex I placed a file (. Reg registry system) that restores the factory settings, and the tab will magically reappear.
This is the download file, double click the file you unpacked and then click on ok the next message.
For those who do not trust the contents of this file is:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer]
“NoActiveDesktopChanges” = hex: 00,00,00,00
“NoActiveDesktop” = dword: 00000000
“NoSaveSettings” = dword: 00000000
“ClassicShell” = dword: 00000000
“NoThemesTab” = dword: 00000000

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System]
“NoDispAppearancePage” = dword: 00000000
“NoColorChoice” = dword: 00000000
“NoSizeChoice” = dword: 00000000
“NoDispBackgroundPage” = dword: 00000000
“NoDispScrSavPage” = dword: 00000000
“NoDispCPL” = dword: 00000000
“NoVisualStyleChoice” = dword: 00000000
“NoDispSettingsPage” = dword: 00000000
“NoDispScrSavPage” = dword: 00000000
“NoVisualStyleChoice” = dword: 00000000
“NoSizeChoice” = dword: 00000000
“SetVisualStyle” =-

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ ActiveDesktop]
“NoChangingWallPaper” = dword: 00000000

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ ThemeManager]
“ThemeActive” = “1″
“DllName” = hex (2): 25,00,53,00,79,00,73,00,74,00,65,00,6 d, 00,52,00,6 f, 00,6 f, 00, \
74,00,25,00,5 c, 00,72,00,65,00,73,00,6 f, 00,75,00,72,00,63,00,65,00,73,00,5 c, \
00,54,00,68,00,65,00,6 d, 00,65,00,73,00,5 c, 00,6 c, 00,75,00,6 e, 00,61,00,5 c, 00, \
6c, 00,75,00,6 e, 00,61,00,2 e, 00,6 d, 00,73,00,73,00,74,00,79,00,6 c, 00,65,00,73, \
00,00,00

A user, fer21, indicates that this virus is removed with combofix (here’s a guide), a tool used to precisely remove spyware and viruses from the pc, unfortunately some antivirus detect it as malicious, and then look at what you do. Incoming Search Terms :



Rate this topic:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Popularity: 245 views

Related Post

You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment