How to remove XP Defender

Monday, March 29th, 2010 at 5:59 am
Home » Rogue Antispyware » XP Defender

XP Defender description

XP Defender annoys its victims with numerous fake security alerts till they decide to buy the program. Purchasing XPDefender doesn’t change a thing since XP Defender is designed to load pop-ups but it’s not able to function as a security program. XP Defender may look like it was made by the Microsoft Corp.; keep in mind that it’s a scam. XP Defender may also present itself as XP Defender Pro.

XP Defender pretends to be a functional tool by displaying scan reports and infection warnings. The real functions of XPDefender are blocking antispyware programs and redirecting web browser to deceptive sources.

Here are some examples of the counterfeit alerts loaded by XP Defender:

Severe system damage!
Spyware and viruses detected in the background. Sensitive system components under attack! Data loss, identity theft and system corruption are possible. Act now, click here for a free security scan.

XP Defender ALERT
System integrity threat!

Warning! Sensitive data may be sent over your internet connection right now!
Details
Attack from: 235.91.44.40 port: 6301
Attacked port: 4637
Threat: Macro.PPoint.ShapeShift

Do you want to block this attack?

XP Defender is a Rogue Antispyware software

How to manually remove XP Defender

To remove XP Defender spyware you must block XP Defender sites, stop and remove processes, unregister DLL files, search and delete all other XP Defender files and registry utility. Follow the XP Defender detection and removal instructions below.

The most typical software removal method is to remove XP Defender by using "Add or Remove Programs" service. However there may be hidden XP Defender files, running processes and registries in your computer, so XP Defender may recreate all other files after reboot.

XP Defender manual removal instructions

Block XP Defender sites:
bestpathsecurity.com Read more how to block XP Defender sites

Stop and remove XP Defender processes:
ave.exe Read more how to kill XP Defender processes

Locate and delete XP Defender registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\secfile\shell
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = "%AppData%\ave.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = "%1" %*
HKEY_CURRENT_USER\Software\Classes\.exe | @ = "secfile"
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | @ = "%AppData%\ave.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | IsolatedCommand = "%1" %*
Read more how to delete XP Defender registry entries
Download RegistryBooster 2010 to scan errors caused by XP Defender

Detect and delete other XP Defender files:
%AppData%\ave.exe

We strongly recommend you to use spyware remover to track XP Defender and automaticaly remove XP Defender processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: ,

4 Responses to

XP Defender

  1. Brian Luther

    The problem I am having, it tends to interrupt any type of action I want to do and I cannot open any browser to do anything (on my main pc).. Any suggestions?

    Reply

    Kevin Vilianos Reply:

    You can try booting in Safe Mode (Press f8 during bootup) and from there start the task manager as soon as possible. Kill the ave.exe process and try to use your computer to remove it from there.

    Reply

    Robert Reply:

    instead of clicking on an object, right click and open in new tab.
    it worked for me :)

    Reply

Trackbacks

Leave a Reply

Download does not start? Try a mirror download here