XP Security 2013

By ZulaZuza in Rogue Anti-Virus Program | 277 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 3.50 out of 5)
Loading ... Loading ...
More... More

XP Security 2013 Description

Image Screenshot

[+] Click Image to Enlarge

XP Security 2013 is a dangerous anti-virus program that propagates with the help of Trojans. XP Security 2013 tries to imitate a trustworthy and powerful security program by pretending to scan the compromised PC and detect malware infections on the computer system, which, in truth, are absolutely false. XP Security 2013 attempts to convince victims to purchase its so-called full version to remove those supposed PC infections. XP Security 2013 was created by cybercriminals with the only aim to deceive unsuspecting computer users and swindle them out of their money. XP Security 2013 has no capability of detecting and removing any type of malware threats. Once installed, XP Security 2013 immediately starts displaying fake pop-up warning messages to intimidate you into thinking that your PC is compromised. In reality, your computer has been corrupted by malware, but the real security threat is XP Security 2013 itself, which has to be removed as soon as possible with a genuine security program. ESG’s security analysts highly recommend you not to believe anything associated with XP Security 2013 and purchase this malware application.

Type: Rogue Anti-Virus Program

How Can You Detect XP Security 2013?

XP Security 2013 Technical Report

As new XP Security 2013 details are reported by our customers and findings from our Threat Research Center, we will update this section.

Fake message for XP Security 2013:

The following fake error message(s) appears for XP Security 2013:

XP Security 2013 Removal Details

XP Security 2013 has typically the following processes in memory:

  • %LocalAppData%\[RANDOM CHARACTERS].exe

XP Security 2013 creates the following files in the system:

  • %LocalAppData%\[RANDOM CHARACTERS]
  • %Temp%\[RANDOM CHARACTERS]
  • %AppData%\Roaming\Microsoft\Windows\Templates\[RANDOM CHARACTERS]
  • %CommonAppData%\[RANDOM CHARACTERS]

XP Security 2013 creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Classes\ “(Default)” = ‘Application’
  • HKEY_CURRENT_USER\Software\Classes\\DefaultIcon “(Default)” = ‘%1′
  • HKEY_CLASSES_ROOT\ah\shell\open\command “IsolatedCommand”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “”%LocalAppData%\.exe -a “C:\Program Files\Mozilla Firefox\firefox.exe”"
  • HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ”
  • HKEY_CURRENT_USER\Software\Classes\\shell\open\command “(Default)” = “%LocalAppData%\.exe” -a “%1″ %*
  • HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “%LocalAppData%\.exe” -a “%1″ %*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “”%LocalAppData%\.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode”
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “%LocalAppData%\.exe” -a “%1″ %*
  • HKEY_CLASSES_ROOT\
  • HKEY_CLASSES_ROOT\ah\shell\open\command “(Default)” = “%LocalAppData%\.exe” -a “%1″ %*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “”%LocalAppData%\.exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”"

Important Article Disclaimer

ESG Support Center

This entry was last updated on 01/13/13 and posted on 10/8/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.