<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techie Xplorer &#187; Security</title>
	<atom:link href="http://www.techiexplorer.com/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.techiexplorer.com</link>
	<description>Xploring Gadgets, Computing and Technology</description>
	<lastBuildDate>Thu, 29 Jul 2010 09:06:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>McAfee update breaks Windows XP computers</title>
		<link>http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html</link>
		<comments>http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html#comments</comments>
		<pubDate>Thu, 22 Apr 2010 20:51:50 +0000</pubDate>
		<dc:creator>sylv3rblade</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[5958]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[Virus Definition]]></category>

		<guid isPermaLink="false">http://www.techiexplorer.com/?p=255</guid>
		<description><![CDATA[<p>First it was Nvidia&#8217;s drivers with the <a href="http://www.techiexplorer.com/hardware/nvidia-196-75-breaks-fan-speed-control-overheat-problems.html">fan control speed issues</a> and now it&#8217;s McAfee and their XP killing update.  It seems like a lot of company updates are hitting the fan.</p>
<p><!--more--><br />
The recent update of McAfee for their antivirus software on windows XP is causing computers to shut down and revert to an infinite loop of resets/restarts.  The company has offered the following statement:</p>
<blockquote><p><em>McAfee is aware that a number of customers have  incurred a false positive error due to incorrect malware alerts on  Wednesday, April 21. The problem occurs with the 5958 virus definition  file (DAT) that was released on April 21 at 2.00 PM GMT+1 (6am Pacific  Time).</em></p>
<p><em>Our initial investigation indicates that the error can  result in moderate to significant performance issues on systems running  Windows XP Service Pack 3.</em></p>
<p><em>The faulty update has been removed  from McAfee download servers for corporate users, preventing any further  impact on those customers. We are not aware of significant impact on  consumer customers and believe we have effectively limited such  occurrence.</em></p>
<p><em>McAfee teams are working with the highest priority  to support impacted customers and plan to provide an update virus  definition file shortly. McAfee apologizes for any inconvenience to our  customers</em></p></blockquote>
<p>So what exactly does McAfee&#8217;s 5958 virus definition do that it sends XP computers in an infinite loop of death?   it seems that the 5958 DAT file flags svchost.exe file (a common Windows services file) as malware, deletes it and kills your machine.</p>
<h2>How do I fix a computer that has updated to McAfee&#8217;s 5958 DAT file?</h2>
<p>McAfee recommends the following solution</p>
<ol>
<li>From a computer that has Internet access, locate and download the  	Recovery SuperDAT at <a href="http://download.nai.com/products/mcafee-avert/tools/SDAT5958_EM.exe"> http://download.nai.com/products/mcafee-avert/tools/SDAT5958_EM.exe</a> and  	save it to portable media.</li>
<li>Take the portable media to each affected computer and run the  tool.<strong>NOTE: </strong>If you are  not able to run  	the tool on the affected computer, (re)start your computer in Safe  Mode.<br />
For instructions on starting in Safe Mode, see <a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true"> http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true</a></li>
<li>Run the Recovery SuperDAT tool.</li>
<li>Restart in normal mode.</li>
</ol>
<p>via <a href="http://vil.nai.com/vil/5958_false.htm">here</a></p>
<p>The problem is that you still need a working computer to run download the file.  If you have none, ask a friend for this favor as it&#8217;s the only to recover your machine aside from a complete reinstall.  If you have any questions and/or clarifications, please post them in the comments.</p>
<hr />
<p><small>&copy; sylv3rblade for <a href="http://www.techiexplorer.com">Techie Xplorer</a>, 2010. |
<a href="http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html">Permalink</a> |
<a href="http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html#comments">2 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html&amp;title=McAfee update breaks Windows XP computers">del.icio.us</a>
<br/>
Post tags: <a href="http://www.techiexplorer.com/tag/5958" rel="tag">5958</a>, <a href="http://www.techiexplorer.com/tag/mcafee" rel="tag">McAfee</a>, <a href="http://www.techiexplorer.com/tag/security" rel="tag">Security</a>, <a href="http://www.techiexplorer.com/tag/virus-definition" rel="tag">Virus Definition</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></description>
		<wfw:commentRss>http://www.techiexplorer.com/2010/04/mcafee-update-breaks-windows-xp-computers.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Fake Security Suite in the wild</title>
		<link>http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html</link>
		<comments>http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html#comments</comments>
		<pubDate>Mon, 15 Mar 2010 00:41:40 +0000</pubDate>
		<dc:creator>sylv3rblade</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security Essentials 2010]]></category>

		<guid isPermaLink="false">http://www.techiexplorer.com/?p=205</guid>
		<description><![CDATA[<p>A fake version of Microsoft Security Essentials (MSE), Redmond&#8217;s free antivirus program is quietly spreading under the guise of the original&#8217;s brand recognition.  The rogue &#8220;antivirus&#8221; software is called <strong>Security Essentials 2010</strong>.</p>
<p><!--more--><br />
<a href="http://www.techiexplorer.com/wp-content/uploads/2010/03/security-essentials.jpg"><img class="aligncenter size-large wp-image-223" title="FAKE Antivirus: Security Essentials 2010" src="http://www.techiexplorer.com/wp-content/uploads/2010/03/security-essentials-500x369.jpg" alt="" width="500" height="369"  align="center"/></a></p>
<p>If your computer displays the screenshot shown above, then your system is infected trojan called  TrojanDownloader:Win32/Fakeinit.  Microsoft&#8217;s official statement on the programs describes it as such: <em>fake  scanner that informs the user that they need to pay money to register  the software and remove these non-existent threats</em>, much like past rogue &#8220;antivirus&#8221; softwares like <strong>Antivirus 2009</strong> and <strong>Antivirus 2010</strong>. What&#8217;s worse is that <strong>Security Essentials 2010</strong> also terminates certain processes (like some of the &#8220;weaker&#8221; antivirus programs), edits the registry to disable Task Manager, lowers your  security settings, hijacks your Web browser, and changes your background image to one of an ominious spyware warning.</p>
<p><img src="http://www.techiexplorer.com/wp-content/uploads/2010/03/security_risk_trial.jpg" alt="" class="aligncenter" align="center"/></p>
<h2>How to Remove Fake Security Essentials 2010</h2>
<h3>Manual Method</h3>
<ol>
<li>Clean your System with HijackThis.
<ol>
<li>Download and install <a title="Download Process Explorer" href="http://www.tkqlhce.com/click-1701896-10619284" target="_blank">HijackThis</a>.</li>
<li>Run HijackThis, click <strong>Do a System Scan Only</strong></li>
<li>Select the following entries from the scanned list:<br />
F2 –  REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe<br />
O4 – HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe<br />
O4 – HKCU\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe<br />
O4 – HKCU\..\Run: [Security essentials 2010] C:\Program  Files\Securityessentials2010\SE2010.exe</li>
<li>Close all other applications (except HijackThis of course) and click the <strong>fix checked</strong> button.  This will remove all entries of Security Essentials 2010 from your registry.</li>
<li>Close HijackThis</li>
</ol>
</li>
<li>Clean Security Essentials 2010 DLL files.
<ol>
<li>Download and install LSPFix from <a href="http://www.cexx.org/lspfix.zip">LSPFix</a> and unzip it to your  Desktop.</li>
<li>Run LSPFix and tick the option <strong>I know what I&#8217;m doing</strong> under the Advanced Options.</li>
<li>On the Keep box, click helper32.dll</li>
<li>Press the <strong>&gt;&gt;</strong> button to transfer it to the Remove box.</li>
<li>Press Finish&gt;&gt; button to remove the helper32.dll file.</li>
<li>Once the removal process is done, LSPFix will display a summary of it&#8217;s actions.  Press OK to close it.</li>
</ol>
</li>
</ol>
<h3>Automated Method</h3>
<p>Simply install the following programs, update their database and  scan.</p>
<ul>
<li>The Official <a href="http://www.microsoft.com/security/products/mse.aspx">Microsoft Security Essentials</a> &#8211; Microsoft&#8217;s own security suite has been updated to deal with this fake antivirus program.</li>
<li><a href="http://www.malwarebytes.org/mbam.php">Malwarebytes&#8217;  Anti-Malware</a> is a free tool that removes all traces of Security  Essentials 2010</li>
</ul>
<p>For reference Security Essentials 2010 makes the following additions to your computer:</p>
<h3>Security Essentials 2010 creates the following files and folders</h3>
<p>C:\Program Files\SecurityEssentials2010<br />
C:\Program Files\SecurityEssentials2010\SE2010.exe</p>
<h3>Security Essentials 2010 creates the following registry keys and   values</h3>
<p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Security   Essentials 2010</p>
<p>If you have any other question, post a comment.  Good luck!</p>
<hr />
<p><small>&copy; sylv3rblade for <a href="http://www.techiexplorer.com">Techie Xplorer</a>, 2010. |
<a href="http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html">Permalink</a> |
<a href="http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html&amp;title=Fake Security Suite in the wild">del.icio.us</a>
<br/>
Post tags: <a href="http://www.techiexplorer.com/tag/fake-antivirus" rel="tag">Fake Antivirus</a>, <a href="http://www.techiexplorer.com/tag/security" rel="tag">Security</a>, <a href="http://www.techiexplorer.com/tag/security-essentials-2010" rel="tag">Security Essentials 2010</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></description>
		<wfw:commentRss>http://www.techiexplorer.com/2010/03/fake-security-suite-in-the-wild.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivirus 2009</title>
		<link>http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html</link>
		<comments>http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html#comments</comments>
		<pubDate>Mon, 05 Oct 2009 11:46:46 +0000</pubDate>
		<dc:creator>sylv3rblade</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus 2009]]></category>
		<category><![CDATA[Malware removal]]></category>

		<guid isPermaLink="false">http://techiexplorer.com/?p=14</guid>
		<description><![CDATA[<p>Most of us has experience with Malware but this strain simply takes the cake.  It&#8217;s a rogue application that disguises itself as an antivirus, tells you that your computer is infected as asks you to pay the guy who created it to remove it.</p>
<p><!--more--></p>
<p><a href="http://techiexplorer.com/wp-content/uploads/2009/10/antivirus-2009.jpg"><img class="aligncenter" src="http://techiexplorer.com/wp-content/uploads/2009/10/antivirus-2009.jpg" alt="Screen shot of Antivirus 2009" width="400" align="center" /></a></p>
<h2>How to Remove Antivirus 2009</h2>
<h3>Manual Method</h3>
<ol>
<li><strong></strong>Kill Antivirus 2009 Processes.
<ol>
<li>Download and install <a title="Download Process Explorer" href="http://www.microsoft.com/technet/sysinternals/utilities/processexplorer.mspx" target="_blank">Process Explorer</a>.</li>
<li>Open <strong>Process Explorer</strong>.</li>
<li>Locate the Antivirus 2009 processes listed below.</li>
<li>To kill an Antivirus 2009 process, right-click the Antivirus 2009 process and choose the option <strong>“Kill Process Tree”</strong>.</li>
<li>Kill the following Antivirus 2009 processes:<br />
AntivirusPro2009.exe<br />
%PROGRAMFILES%\Antivirus 2009\av2009.exe<br />
ieexplorer32.exe<br />
AV2009Install[1].exe<br />
Power-Antivirus-2009.exe<br />
c:\WINDOWS\system32\ieupdates.exe<br />
c:\Program Files\Antivirus 2009\av2009.exe<br />
AV2009Install_880405[2].exe<br />
AV2009Install_880405[1].exe<br />
av2009[1].exe<br />
AV2009Install.exe<br />
Antivirus2009.exe<br />
av2009.exe</li>
</ol>
</li>
<li><strong></strong>Kill Antivirus 2009 DLL files.
<ol>
<li>Right-click the <strong>Explorer.exe</strong> process and choose the option <strong>“Properties”.</strong></li>
<li>Click on the <strong>“Threads”</strong> Tab, locate and highlight the Antivirus 2009 DLL files listed below.</li>
<li>To kill Antivirus 2009 DLL files, click the <strong>“Kill”</strong> button.</li>
<li>Kill the following Antivirus 2009 DLL files:<br />
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll<br />
c:\WINDOWS\system32\winsrc.dll</li>
</ol>
</li>
<li><strong></strong>Delete Antivirus 2009 Registry Keys and Values.
<ol>
<li>Right-click on your <strong>Desktop</strong> &gt; select <strong>“New”</strong> option &gt; select <strong>“Text Document”</strong> (.txt file) option.</li>
<li>Rename the .txt file as a .reg file and call it <strong>“Delete_Registry_<br />
Antivirus 2009_Entities.reg”</strong>. This renamed .reg file is a command that creates a shortcut to your Windows registry and allows you to easily delete registry values.</li>
<li>Right-click and select the <strong>“Edit”</strong> option.</li>
<li>Copy and paste the Antivirus 2009 keys listed below.</li>
<li>In the menu bar, go to <strong>“File”</strong> &gt; select <strong>“Save”</strong> &gt; then click the <strong>“X”</strong> button to close the file.</li>
<li>Double-click on the .reg file.</li>
<li>When the message box appears saying <strong>“Are you sure you want to add the information in C:DOCUME~1%username%DesktopDELETE~1.REG to the registry?”</strong>, click the <strong>“Yes”</strong> button.</li>
<li>When the message box appears saying <strong>“Information in C:DOCUME~1<br />
%username%DesktopDELETE~1.REG has been successfully entered into the registry.”</strong>, click the <strong>“OK”</strong> button.</li>
<li>The Antivirus 2009 registry keys have been deleted from your registry.</li>
<li>Copy and paste the following Antivirus 2009 keys:
<pre style="list-style-type: none; list-style-image: none; list-style-position: outside;"><textarea style="font-family: Lucida Grande,Verdana,Arial,Sans-Serif; font-size: 11px; background-color: #fafafa;" cols="60" rows="10" name="textarea">Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\AV2009Install.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\av2009[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\av2009[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\av2009[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\av2009[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\av2009[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\av2009[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\av2009[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\av2009[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\av2009[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\av2009[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Uninstall Antivirus 2009.lnk]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Uninstall Antivirus 2009.lnk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install_880405[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install_880405[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install_880405[2].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install_880405[2].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\Power-Antivirus-2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\Power-Antivirus-2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AV2009Install[1].exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AV2009Install[1].exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\ieexplorer32.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\ieexplorer32.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\ieexplorer32.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\ieexplorer32.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ieexplorer32.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\ieexplorer32.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ieexplorer32.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ieexplorer32.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\ieexplorer32.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\ieexplorer32.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AntivirusPro2009.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\AntivirusPro2009.exe]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\AntivirusPro2009.exe]
</textarea></pre>
</li>
</ol>
</li>
<li><strong></strong>Delete Antivirus 2009 Directories.
<ol>
<li>To locate Antivirus 2009 directories, go to <strong>“Start”</strong> &gt; <strong>“My Computer”</strong> &gt; <strong>“Local Disk (C:)”</strong> &gt; <strong>“Program Files”</strong> &gt; <strong>“Show the contents of this folder”</strong>.</li>
<li>Search and delete the Antivirus 2009 directories listed below.</li>
<li>Right-click on the Antivirus 2009 folder and select <strong>“Delete”</strong>. option.</li>
<li>When the message box appears saying <strong>“Are you sure you want to remove the folder [FOLDERNAME] and move all its contents to the Recycle Bin?”</strong>, click the <strong>“Yes”</strong> button.</li>
<li>When the message box appears saying <strong>“Renaming, moving or deleting [FOLDERNAME] could make some programs not work. Are you sure you want to do this?”</strong>, click the <strong>“Yes”</strong> button.</li>
<li>Search and delete the following Antivirus 2009 directories:<br />
%ProgramFiles%\AntivirusPro2009<br />
%ProgramFiles%\AV9<br />
%ProgramFiles%\Power-Antivirus-2009<br />
%UserProfile%\Start Menu\Antivirus 2009<br />
%ProgramFiles%\Antivirus 2009</li>
</ol>
</li>
<li><strong></strong> Restore Original Default Home Page.
<ol>
<li>Go to <strong>“Start”</strong> &gt; <strong>“Control Panel”</strong> &gt; <strong>“Internet Options”</strong>.</li>
<li>Click on the <strong>General</strong> Tab &gt; click the <strong>Use Default</strong> button under Home Page.</li>
<li>Click <strong>“Apply”</strong> and then click the <strong>“OK”</strong> button.</li>
<li>Open a Web browser to verify that your default homepage has been restored.</li>
</ol>
</li>
<li><strong></strong>Remove the Antivirus 2009 Icons.
<ol>
<li>If the Antivirus 2009 icons still remain on your Desktop, you can drag and drop them to the <strong>“Recycle Bin”</strong>.</li>
<li>Reboot your computer to make sure all changes made for the removal of Antivirus 2009 are complete. If your computer still has issues, you should scan your computer for Antivirus 2009 with a spyware scanner.</li>
</ol>
</li>
</ol>
<h3>Automated Method</h3>
<p>Simply install the following programs, update their database and scan.</p>
<ul>
<li><a href=" http://www.microsoft.com/downloads/">MSRT from Microsoft</a></li>
<li><a href="http://www.malwarebytes.org/mbam.php">Malwarebytes&#8217; Anti-Malware</a> is a free tool that removes all traces of Antivirus 2009</li>
<li><a href="http://www.emsisoft.com/en/software/antimalware/">A-squared Anti-Malware</a> is another free tool that will remove all traces of Antivirus 2009</li>
</ul>
<p>Good luck!</p>
<hr />
<p><small>&copy; sylv3rblade for <a href="http://www.techiexplorer.com">Techie Xplorer</a>, 2009. |
<a href="http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html">Permalink</a> |
<a href="http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html&amp;title=How to Remove Antivirus 2009">del.icio.us</a>
<br/>
Post tags: <a href="http://www.techiexplorer.com/tag/antivirus-2009" rel="tag">Antivirus 2009</a>, <a href="http://www.techiexplorer.com/tag/malware-removal" rel="tag">Malware removal</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></description>
		<wfw:commentRss>http://www.techiexplorer.com/2009/10/how-to-remove-antivirus-2009.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove JARGON.VBS</title>
		<link>http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html</link>
		<comments>http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html#comments</comments>
		<pubDate>Thu, 01 Oct 2009 23:33:27 +0000</pubDate>
		<dc:creator>sylv3rblade</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Jargon.vbs]]></category>
		<category><![CDATA[Malware removal]]></category>

		<guid isPermaLink="false">http://techiexplorer.com/?p=9</guid>
		<description><![CDATA[<p>I&#8217;ve encountered this virus/malware the other day and while it was fairly easy to remove, I thought it would be useful to provide instructions on how to remove jargon.vbs.  A quick search on GOOG turned out several useless results (okay, a lot of useless results) so I thought of doing my part to help.  </p>
<p>Here&#8217;s how you can remove JARGON.VBS from your computer and your infected flash drives.<br />
<!--more--></p>
<ul>
<li>Download: <a href="http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe">Flash Disinfector</a> | <a href="http://ifile.it/0ge9lp3">Mirror</a></li>
<li>Run the Flash_Disinfector.exe.  Explorer will close (your desktop will disappear leaving you with windows of currently running programs) and restart.  This will have stopped the script.</li>
<li>Now you&#8217;ll have to delete the malware files so your system won&#8217;t get infected again, to do this you need to display hidden files.
<ul>
<li>Open My Computer.</li>
<li>Select the Tools menu and click Folder Options.</li>
<li>Select the View Tab.</li>
<li>Under the Hidden files and folders heading unselect Do not show hidden files and folders.</li>
<li>Browse your flash drive (DON&#8217;T CLICK AUTOPLAY or you&#8217;ll run the malware again) and remove the following files:</li>
<pre class="brush: vb;">
autorun.inf
jargon.vbs
wscript.exe
</pre>
<p>Repeat this step for all infected drives.</p>
<li>Go to <strong>C:/Windows</strong> and delete</li>
<pre class="brush: vb;">
jargon.vbs
</pre>
</ul>
</li>
<li>Congratulations, you&#8217;ve removed that annoying malware</li>
</ul>
<hr />
<p><small>&copy; sylv3rblade for <a href="http://www.techiexplorer.com">Techie Xplorer</a>, 2009. |
<a href="http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html">Permalink</a> |
<a href="http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html#comments">20 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html&amp;title=How to remove JARGON.VBS">del.icio.us</a>
<br/>
Post tags: <a href="http://www.techiexplorer.com/tag/jargon-vbs" rel="tag">Jargon.vbs</a>, <a href="http://www.techiexplorer.com/tag/malware-removal" rel="tag">Malware removal</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></description>
		<wfw:commentRss>http://www.techiexplorer.com/2009/10/how-to-remove-jargon-vbs.html/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>
