How to remove Homesiterenew.com/security/xp
Wednesday, December 3rd, 2008 at 12:40 pmHome » Browser Hijacker, Malicious domains » Homesiterenew.com/security/xp
Homesiterenew.com/security/xp description
Homesiterenew.com/security/xp browser hijacker is related to the infamous Zlob trojan. The scammers didn’t even bother to create a new website: homesiterenew.com/security/xp is identical to many sites created to promote Ultra Antivirus and Windows Antivirus 2008. Homesiterenew.com/security/xp pushes visitors into buying AntiVirus Trigger. The hijacker loads the following message:
“Warning!
W32.Myzor.FK@yf is a virus that infects files with .exe extensions. It attempts to steal passwords and private information from the infected computer.
Type: Virus
Infection Length: 138,293 bytes
Systems Affected: Windows 95, 98, ME, NT (all versions), 2003, Windows XP (all service packs)
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical details: 1. Creates files in %Windir%\ directory. By default, this is C:\Windows.
2. Adds values to registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
3. Scans the hard drive for .exe files and infects any executable files.
Searches for passwords/information, which it may send to a remote attacker.
Recomendations: Click “OK” to download officially approved security software.
Always keep your patch levels up-to-date.”
If clicked upon, the message offers downloading AntiVirusTrigger.

If your computer is infected with AntiVirusTrigger , follow AntiVirusTrigger removal guide.
How to manually remove Homesiterenew.com/security/xp
To remove Homesiterenew.com/security/xp spyware you must block Homesiterenew.com/security/xp sites, stop and remove processes, unregister DLL files, search and delete all other Homesiterenew.com/security/xp files and registry utility. Follow the Homesiterenew.com/security/xp detection and removal instructions below.
The most typical software removal method is to remove Homesiterenew.com/security/xp by using "Add or Remove Programs" service. However there may be hidden Homesiterenew.com/security/xp files, running processes and registries in your computer, so Homesiterenew.com/security/xp may recreate all other files after reboot.
Homesiterenew.com/security/xp manual removal instructions
Block Homesiterenew.com/security/xp sites:
homesiterenew.com
Read more how to block Homesiterenew.com/security/xp sites
Stop and remove Homesiterenew.com/security/xp processes:
nvctrl.exe
msmsgs.exe
icmntr.exe
icthis.exe
ictun.exe
icun.exe
isfmm.exe
isfmntr.exe
isfun.exe
Read more how to kill Homesiterenew.com/security/xp processes
Locate and delete Homesiterenew.com/security/xp registry entries:
e3623691-f85d-48d8-8e4d-abe79077f841
2f199d0e-f3e7-41a7-a060-816c24cceea0
0ba3e00d-b660-46e6-a2db-2672ee82dc98
c96395b8-ab09-46a4-b539-7ddf6e061808
ba934431-76af-4c99-93c2-c3d21944a72e
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Bar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer Security Plug-in
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}
Read more how to delete Homesiterenew.com/security/xp registry entries
Download RegistryBooster 2010 to scan errors caused by Homesiterenew.com/security/xp
Search and unregister Homesiterenew.com/security/xp DLL libraries:
duzakwq.dll
zafhemm.dll
Read more how to unregister Homesiterenew.com/security/xp DLL files
Detect and delete other Homesiterenew.com/security/xp files:
icmntr.exe
icthis.exe
ictun.exe
icun.exe
isfmm.exe
isfmntr.exe
isfun.exe
pmuninst.exe
gtawclv.dll
pmmon.exe
duzakwq.dll
zafhemm.dll
spwoqbmv.exe
xbaqktfv.exe
We strongly recommend you to use spyware remover to track Homesiterenew.com/security/xp and automaticaly remove Homesiterenew.com/security/xp processes, registries and files as well as other spyware threats.

