XP Antispyware 2010 spreads via trojans and deceptive online advertisements.
Avoid installing this program if you have a choice.
XP Antivirus Pro 2010 (also can be met as XP Antivirus Pro) is a rogue anti-spyware
application. It uses false scan results and fake security warnings in order to
scare you into purchasing this bogus software. It states that your computer is
infected with Trojans, adware or malware and that you should purchase XP
Antivirus Pro 2010 to remove the infections that of course don't even exist.
This parasite is advertised through the use of Trojans. It's also promoted on
various malicious websites. Once active, this parasite will ostensibly scan your
computer and list various fake infections or security threats. It will also
flood your computer with very annoying pop-ups and security alerts. One of such
fake security alerts states:
XP Antivirus Pro 2010 manual removal:
Kill processes:
av.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\secfile\shell
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\av.exe”
/START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand =
“”%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “secfile”
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | @ = “”%AppData%\av.exe”
/START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command |
IsolatedCommand = “”%1″ %*”
Delete files:
%UserProfile%\\Local Settings\\Application Data\\av.exe %UserProfile%\\Local
Settings\\Application Data\\WRblt8464P