FrEn

Envoyer Imprimer

Free malware removal tool to remove Win Antispyware Center

Écrit par Administrator  |  Samedi, 22 Mai 2010 18:49
AddThis Social Bookmark Button
There are no translations available.

Win Antispyware Center is another rogue Antispyware, another malware that pretends to be an Antivirus. Win Antispyware Center conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Win Antispyware Center. It invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Win Antispyware Center immediatly from your system.

Win Antispyware Center

To remove Win Antispyware Center (Uninstall Win Antispyware Center)

  • Download this free removal tool for Win Antispyware Center
  • Extract it
  • Launch
  • Click on the delete button

Win Antispyware Center will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :

  • av.exe

Files :

  • %ProgramFiles%\WinAntispywareCenter\av.exe
  • %ProgramFiles%\WinAntispywareCenter

Registry

Registry keys created

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell\open
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell\open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\DefaultIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\open
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\runas
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\runas\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\start
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\start\command
  • HKEY_CURRENT_USER\Software\Microsoft\Multimedia\DrawDib
  • HKEY_CURRENT_USER\Software\Classes\.exe
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\secfile
  • HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
  • HKEY_CURRENT_USER\Software\Win Antispyware Center

Registry values created

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell\open\command
    • (Default) = ""%ProgramFiles%\WinAntispywareCenter\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\open\command
    • (Default) = ""%ProgramFiles%\WinAntispywareCenter\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\runas\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\shell\start\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile\DefaultIcon
    • (Default) = "%1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile
    • (Default) = "Application"
    • Content Type = "application/x-msdownload"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • Win Antispyware Center = "%ProgramFiles%\WinAntispywareCenter\av.exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Multimedia\DrawDib
    • vga.drv 640x480x32(BGR 0) = "31,31,31,31"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • Win Antispyware Center = "%ProgramFiles%\WinAntispywareCenter\av.exe"
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
    • (Default) = ""%ProgramFiles%\WinAntispywareCenter\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
    • (Default) = ""%ProgramFiles%\WinAntispywareCenter\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
    • (Default) = "%1"
  • HKEY_CURRENT_USER\Software\Classes\secfile
    • (Default) = "Application"
    • Content Type = "application/x-msdownload"
  • HKEY_CURRENT_USER\Software\Win Antispyware Center
    • defaultCfg = "%Windir%\inf\McVfUydyG.CA;5001;%Windir%\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\AWGbToyq.exe;2;%Windir%\pchealth\helpctr\System\images\Expando\ugcxjMxZUmY.JT;7;%System%\HlswUFlkgJq.R;4;%System%\KEnIyXsDnjW.Vhu;
    • first = "1"

 

Download

 

 

Articles connexes
Derniers articles

No data

.
Information | Contact

© All Rights Reserved. net-studio.org 2009