How to remove XP Internet Security
Tuesday, February 2nd, 2010 at 2:13 amHome » Rogue Antispyware » XP Internet Security
XP Internet Security description
XP Internet Security belongs to a new wave of rogue anti-spyware tools. It changes its appearance depending on Windows version found on victim’s PC. This means that the same program will appear as XP InternetSecurity on Windows XP, but it will present itself as Vista Guardian 2010 on Windows Vista and it may appears as Win 7 Antispyware 2010 on Windows 7 operating system.
XPInternetSecurity puts all the efforts to convince people that it is a legitimate program made by Microsoft Corp. Keep in mind that XPInternet Security is a malware. It’s able to mimic security alerts and notifications but it is a danger to your computer and your privacy and your money.
XP Internet Security is a Rogue Antispyware software
How to manually remove XP Internet Security
To remove XP Internet Security spyware you must block XP Internet Security sites, stop and remove processes, unregister DLL files, search and delete all other XP Internet Security files and registry utility. Follow the XP Internet Security detection and removal instructions below.
The most typical software removal method is to remove XP Internet Security by using "Add or Remove Programs" service. However there may be hidden XP Internet Security files, running processes and registries in your computer, so XP Internet Security may recreate all other files after reboot.
XP Internet Security manual removal instructions
Stop and remove XP Internet Security processes:
pw.exe
MSASCui.exe
Read more how to kill XP Internet Security processes
Locate and delete XP Internet Security registry entries:
HKEY_CURRENT_USER\Software\Classes\pezfile
HKEY_CLASSES_ROOT\pezfile
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CLASSES_ROOT\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Read more how to delete XP Internet Security registry entries
Download RegistryBooster 2010 to scan errors caused by XP Internet Security
Detect and delete other XP Internet Security files:
%UserProfile%\Local Settings\Application Data\opRSK
%UserProfile%\Local Settings\Application Data\pw.exe
%UserProfile%\Local Settings\Application Data\MSASCui.exe
%UserProfile%\AppData\Local\opRSK
%UserProfile%\AppData\Local\pw.exe
%UserProfile%\AppData\Local\MSASCui.exe
We strongly recommend you to use spyware remover to track XP Internet Security and automaticaly remove XP Internet Security processes, registries and files as well as other spyware threats.



March 6th, 2010 at 9:29 am
Thank you. Before seeing this entry, I had stopped the av.exe task, and deleted av.exe and the associated xjdhedf file. Upon rebooting, nothing would start. From this item, I found that I needed to get rid of some registry entries. Once I got rid of those, everything started working again. So thanks again.
Reply