Description of XP Anti-spyware 2011 and consequences of its residing on your PC

Many programs offer their help just to get installed on computer systems. Then they either extort money or spy – or both at once.
XP Anti-spyware 2011 is an off-type annoying  antivirus as it more relies on deeds than on verbal influence. In the wild, it tends to combine alerts and malicious actions. For example, saying that the application has failed to start because of virus attack, it attacks the application instead of the virus and may even disable it until relevant  fix is provided.
XP Anti-spyware 2011 Technical Details:

  • Full name: XP Anti-spyware 2011, XP-Anti-spyware 2011, XPAnti-spyware 2011
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian Federation

Signs of being infected with XP Anti-spyware 2011

There is just marginal probability of any detection difficulties when dealing with adware, even in the case of  adware that does not show too much popups.  On the other hand, the counterfeited tool under review does not show few popups, too, and is quite annoying application.
Detection issues usually occur where there  is a security tool of rather poor quality that can interfere with the badware but cannot completely clean it. In such a case the system is likely to freeze repeatedly and popups of the adware may be blocked, partially or completely.
Regular signs of the adware include a variety of popups, including its main user’s interface containing window faking scan progress and summary.
XP Anti-spyware 2011 automatical removal:

Manual Removal of XP Anti-spyware 2011:

Do not underestimate the threat of adware. It  is more dangerous than a virus in some aspects so that XP Anti-spyware 2011 deletion is  to be handled with care. The following precautions are recommended during XP Anti-spyware 2011 removal: system reboot in Safe Mode; preventing other software from functioning; double-checking the below indicated entries before ordering their deletion.

Remove XP Anti-spyware 2011 files and dll’s:

%UserProfile%\Local Settings\Application Data\opRSK
%UserProfile%\Local Settings\Application Data\pw.exe
%UserProfile%\Local Settings\Application Data\MSASCui.exe

Unregister XP Anti-spyware 2011 registry values:

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CLASSES_ROOT\pezfile\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1”

