Backdoor.Win32.TheThing.a screenshot:
Backdoor.Win32.TheThing.a removal tool:
Backdoor.Win32.TheThing.a manual removal instructions:
Delete Backdoor.Win32.TheThing.a files and disable dll's:
shlwapi.dll
wininet.dll
antiVirus2008.exe
shlwapi.dll
wininet.dll
antiVirus2008.exe
htpp://Antivirus-2008-pro.com
htpp://Antivirus-2008-pro.info
htpp://Antivirus-2008-pro.net
htpp://Antivirus-2008-pro.org
htpp://Antivirus-2008pro.com
htpp://Antivirus-2008pro.info
htpp://Antivirus-2008pro.net
htpp://Antivirus-2008pro.org
htpp://Antivirus2008pro.com
htpp://Antivirus2008pro.info
htpp://Antivirus2008pro.net
htpp://Antivirus2008pro.org
XP Security Center.exeDelete XP Security Center registry entries:
mp3avi.dll
XunLeiBHO_Now.dll
alisj.dll
VideoMP3.dll
PowerVideo.dll
XP Security Center.lnk
sysdivx.dll
windivx.dll
Microsoft\Windows\CurrentVersion\App Paths\XP Security Center.exe
09D72564-27E2-4F12-8AB6-03F83E4567DE
741403DD-46A4-4D58-8FA7-427335C3BBF6
2B659BB5-3E85-4BC6-BAFC-98FEDFF3AE99
0EEDB911-C5FA-486F-8334-57288578C627
F10587E9-0E47-4CBE-84AE-7DD20B8685CC
AXPDefender.exeDelete AdvancedXPDefender registry entries:
AXPDefender.exe.local
AXPDefenderSkin.dll
database.dat
license.txt
MFC71.dll
MFC71ENU.DLL
msvcp71.dll
msvcr71.dll
Uninstall.exe
c:\Documents and Settings\All Users\Desktop\AXPDefender.lnk
Advanced XP Defender
Advanced XP Defender.lnk
Advanced XP Defender.lnk
How to register.lnk
License Agreement.lnk
Register.lnk
Uninstall.lnk
Quick Launch\AXPDefender.lnk
HKEY_LOCAL_MACHINE\SOFTWARE\AXPDefender
HKEY_LOCAL_MACHINE\SOFTWARE\AXPDefender\AXPDefender
HKEY_LOCAL_MACHINE\SOFTWARE\AXPDefender\AXPDefender\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\AXPDefender
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “AXPDefender”
AntiMalwareGuard .exeDelete AntiMalwareGuard registry entries:
AntiMalwareGuard .lnk
AntiMalwareGuard .url
AntiMalwareGuard.exe
AntiMalwareGuard0.dll
AntiMalwareGuard1.dll
AntiMalwareGuard3.dll
AntiMalwareGuard.lic
AntiMalwareGuard0.ad
AntiMalwareGuard1.ad
Uninstall AntiMalwareGuard .lnk
Uninstall AntiMalwareGuard.lnk
AntiMalwareGuard.lnk
AntiMalwareGuard_Free[1].exe
Windows\CurrentVersion\Uninstall\
AntiMalwareGuard
Microsoft\Windows\CurrentVersion\Run\AntiMalwareGuard
KvmSecure.lnkDelete KvmSecure registry keys and subkeys:
KvmSecure.lnk
KvmSecure.lnk
KvmSecure.exe
vscan.tsi
zlib.dll
HKEY_CURRENT_USER\Software\KvmSecure\"Autorun" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"RegisterShellExtension" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"CheckForUpdates" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"QuickScanAtStartup" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"StartMinimized" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ID" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ScanArchives" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ScanFiles" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ScanMail" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ScanProcesses" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"ScanRegistry" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"BasesVersion" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"CoreVersion" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"TotalScans" = "1"
HKEY_CURRENT_USER\Software\KvmSecure\"Signatures" = "0"
HKEY_CURRENT_USER\Software\KvmSecure\"lastScanDate" = "130507D7"
HKEY_CURRENT_USER\Software\KvmSecure\"lastScanTime" = "07040033"
HKEY_CURRENT_USER\Software\KvmSecure\"lastUpdateDate" = "0"
HKEY_CURRENT_USER\Software\KvmSecure\"lastUpdateTime" = "0"
