Manual Removal of W32/XPAntivirus.TF Trojan
Manual Removal of W32/XPAntivirus.TF Trojan
The trojan may be dropped by other malware or may be downloaded from remote website by other malware.
It may also be downloaded unknowingly by a user while visiting malicious Website.
This Trojan first appeared on October 8, 2008.
Other names of W32/XPAntivirus.TF Trojan:
This Trojan is also known as
VirTool:Win32/Obfuscator.BI, Mal/EncPk-CZ, not-a-Virus:FraudTool.Win32.XPAntivirus.tf.
Distribution Level: High/ Medium
There is NO Auto Removal Tool for W32/XPAntivirus.TF Trojan
Recommend Removal from Safe Mode:
How to Start in Safe mode:
Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.
The Infected Files Can be Seen in these folders and names also Running in Tasks
End the Following Active Process Before Removal
- %Program Files%\rhcjg7j0e38v\rhcjg7j0e38v.exe
- %Program Files%\rhcjg7j0e38v\msvcp71.dll
- %Documents and Settings\[User Name]
\Local Settings\Temporary Internet Files\Recent\images of xpantivirus2008.lnk - %Documents and Settings\
[User Name] \Local Settings\Temporary Internet Files\Recent\ New Text Document.txt.lnk - Task Manager Running Processes
XPAntivirus.exe
xpa.exe
xpa2008.exe
XPAntivirusUpdate.exe - %Program Files\XPAntivirus\
xpa.exe
xpa2008.exe
XPAntivirus.exe
XPAntivirusUpdate.exe
shlwapi.dll
wininet.dll
XP antivirus
XPAntivirus.lnk
Uninstall XPAntivirus.lnk
XPAntivirus on the Web.lnk
XPAntivirus.url
XPAntivirus2008.lnk
Uninstall XPAntivirus2008.lnk If you have any of these files in running process from task manger, end the process before removal.
Note: if task manager is disabled, Download the following file, Click to Download - Enable Registry.reg
To un-register the .dll Files
Click Start, and then click Run.
Type, or copy and paste, the following text:
regsvr32 /u shlwapi.dll
then click OK.
regsvr32 /u wininet.dll
then click OK.
Manually Remove From Registry
Click Start, Run,Type regedit,Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Download and run this UnHookExec.inf, and then continue with the removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XP antivirus_is1
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\”XP antivirus” = “C:\Program Files\XPAntivirus\XPAntivirus.exe”
XP antivirus
HKEY_USERS\Software\XP antivirus
Search Registry For Virus File Names listed above to remove completely,
Edit Menu - Find, enter Keyword and remove all value that find in search.
Exit the Registry Editor,
Restart your Computer.
Recommended Removal Tools:
Kaspersky Antivirus or Internet Security (Shareware)
Spyware Doctor (Shareware)
AVG Antivirus (Freeware)
Killbox (Freeware)
Written by FireFly. Read more great feeds at is source WEBSITE
no comments.
Read more articles on manual removal and trojan removal and W32/XPAntivirus.TF Trojan and Removal and removal of trojan and antivirus and otherSoftware and Windows.
- [+] Digg: Feature this article
- [+] Del.icio.us: Bookmark this article
- [+] Furl: Bookmark this article
















