Afghan 13 worm

Posted by elise in Blog Worm on March 28th, 2011 | 1 Comment

Tips: Click here to remove Afghan 13 worm Effecitvely

Definition:

How to remove Afghan 13 worm? Afghan 13 worm is characterized as a terrible malware which features in reproducing, mutating and spreading itself via email attachments, system vulnerability and other compromised application attachments. It has embedded special payload to sneak into your system to record your sensitive or private information and track your browser behaviors silently. Afghan 13 worm always comes with malicious toolkits that bundle with Trojans and other malware.

Why do we need to remove Afghan 13 worm?

Afghan 13 worm is regarded as a terrible malware not only because it can silently abuse your sensitive information, but also it may drive you mad by the problems below:

  • Blue Screen of Death errors
  • Memory dump
  • System freezes
  • Slow compute performance( Speed UP PC)
  • .dll errors, .exe errors and runtime errors
  • Crucial system files corruption
  • System 32 errors( Free Detect Errors)
  • Ads bombard
  • Trojan and spyware

How to remove Afghan 13 worm manually?

1. Remove Afghan 13 worm Registry Values:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4

HKEY_LOCAL_MACHINE SYSTEMCurrentControlSetServicesSharedAccessStart=4HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWindowsTaskService(32-bits)

HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWindows Task Service (32-bits)

2. Delete Afghan 13 worm directories:

local.exe

tasksys.exe,

local.exetasksys.exe

Caution! If you need to remove Afghan 13 worm instantly, we sincerely suggest you not solve the problem manually. This is due to this terrible malware has embedded malicious payload to prevent any manual removal. The best way to remove Afghan 13 worm is to it with an awarded Afghan 13 worm remover.

How to remove Afghan 13 worm efficiently and instantly?

Afghan 13 worm is defined as a terrible malware that can result in slow computer performance, system shutdown and obscure computer errors. If you need to remove Afghan 13 worm instantly, we highly recommend you to make a comprehensive scan for your computer with an awarded Afghan 13 worm remover. An awarded Afghan 13 worm remover is especially designed to provide each user with ultimate, powerful and instant protection to thoroughly block and remove Afghan 13 worm and other malware, to make sure that your computer is definitely clean and safe.

Steps to Remove Afghan 13 worm Instantly:

TIBS Dialer

What is TIBS Dialer?
TIBS Dialer is a dialer program that can be used to access various Web sites by dialing a high-cost phone number with the modem. It works by disconnecting a user’s computer from local Internet provider and dialing toll numbers that related to paid or pornographic sites. TIBS Dialer is usually distributed via spam E-mail or certain affiliate websites.

Different from other spyware programs, TIBS Dialer does not steal personal data or affect computer performance. However, it dials premium phone numbers via modem and brings high financial charges.

Do you have TIBS Dialer?
If you have enough time and expertise, you can search your computer for TIBS Dialer manually. However, it might take hours to find out all files of TIBS Dialer, and it is possible that TIBS Dialer will appear after rebooting, for its hidden files may still be there.

Download automatic scanner for TIBS Dialer
Spyware Cease – the technology-oriented security protection that provides a risk-free computing environment for your home and office – with detection, removal and guard in one intuitive and straight-forward interface. Only Spyware Cease gives you individual fix against the most dangerous spyware problems.

Manual TIBS Dialer removal instructions
WARNING: The manually removal method is for advanced users.  TIBS Dialer manually removal can be difficult and time-consuming. There is no guarantee that  TIBS Dialer can be completely removed, for there are hundreds of files generated when  TIBS Dialer installed on your system. Make sure to back up your computer in case that you make any mistakes and your system does not work.

Follow the instructions below for TIBS Dialer removal manually:

Navigate and stop the TIBS Dialer processes:
109512.exe
124837.exe
1248378.exe
paytime.exe
tibs3.exe
tibs.exe
hotandwet.exe
tibs.exe
tibs3.exe
hotandwet.exe

Navigate and delete TIBS Dialer files:
C:\Program Files\PayPerViewDialDialer\HOTANDWET.EXE

What are the symptoms of TIBS Dialer?

  • TIBS Dialer may release commercial advertisements
  • TIBS Dialer may connect itself to the TIB system’s private network
  • TIBS Dialer may stay resident in background
  • TIBS Dialer may dial premium phone numbers with modem
  • TIBS Dialer may be used to access pornographic web sites

How do I keep away from TIBS Dialer
Once you have cleaned up TIBS Dialer, the most important point to prevent TIBS Dialer and future malicious programs from reverting is to stay suspicious of spam E-mail attachment and unknown websites. Here are several ways in which you can help protect your computer against TIBS Dialer and other malware:

  • Use a computer firewall
  • Confirm that you have downloaded all the latest critical security updates
  • Adjust Internet Explorer web browser’s security settings
  • Download and install anti-spyware protection, such as, Spyware Cease
  • Surf sites and download programs from the web sites you trust

What is Dialer?
TIBS Dialer is a type of Dialer.

Dialer is a program that accesses a user’s phone line via a phone-connected modem. Dialers can modify the user’s dial-up settings and make very expensive long distance phone calls without his permission, costing the user significant long distance charges.

XP AntiVirus 2008

What is XP AntiVirus 2008?
XP AntiVirus 2008 is a rogue anti-spyware program that installs itself on your computer without your knowledge or permission. XP AntiVirus 2008 always uses high-pressure tactics by generating fake system error messages to trick user into buying its “Full” version.

XP AntiVirus 2008 may install in your computer when you download a different shareware or freeware program, or when you encounter a drive-by installation on an unsafe webpage. XP AntiVirus 2008 will pop up a series of advertisements which looks like scan results from an antivirus program telling you that you are infected with a number of computer viruses, as well as adware and spyware infections that could immediately harm your computer.You should realize that even though you are told by the fake scans of XP AntiVirus 2008 that your computer is infected by dangerous files, in almost all cases, you do not.

Do you have XP AntiVirus 2008?
If you have enough time and expertise, you can search your computer for XP AntiVirus 2008 manually. However, it might take hours to find out all files of XP AntiVirus 2008, and it is possible that XP AntiVirus 2008 will appear after rebooting, for its hidden files may still be there.

Download automatic scanner for XP AntiVirus 2008
Spyware Cease – the technology-oriented security protection that provides a risk-free computing environment for your home and office – with detection, removal and guard in one intuitive and straight-forward interface. Only Spyware Cease gives you individual fix against the most dangerous spyware problems.

Manual XP AntiVirus 2008 removal instructions
WARNING: The manually removal method is for advanced users. XP AntiVirus 2008 manually removal can be difficult and time-consuming. There is no guarantee that XP AntiVirus 2008 can be completely removed, for there are hundreds of files generated when XP AntiVirus 2008 installed on your system. Make sure to back up your computer in case that you make any mistakes and your system does not work.

Follow the instruction below for XP AntiVirus 2008 removal manually:

Navigate and stop XP AntiVirus 2008 processes:
%program_files%xpantivirusxpantivirusupdate.exe
xpantivirus.exe
download.exe
%program_files%xpantivirussysbackupntoskrnl.exe
install_xp.exe
%program_files%xpantivirussysbackupntoskrnl.exe.md5
%program_files%xpantivirussysbackupexplorer.exe.md5
%program_files%xpantivirusunins000.exe
xpantivirusupdate.exe
%program_files%xpantivirussysbackupexplorer.exe
%program_files%xpantivirusunins000.exe
install_xp.exe
%program_files%xpantivirusxpantivirusupdate.exe
%program_files%xpantivirussysbackupntoskrnl.exe
%program_files%xpantivirussysbackupexplorer.exe
%program_files%xpantivirusxpantivirus.exe
%program_files%xpantivirusxpantivirus.exe

Navigate and Unregister XP AntiVirus 2008 DLL Files:
%program_files%xpantivirussysbackupwininet.dll
%program_files%xpantivirussysbackupshlwapi.dll.md5
%program_files%xpantivirussysbackupshlwapi.dll
%program_files%xpantivirussysbackupwininet.dll.md5
%program_files%xpantivirussysbackupwininet.dll
%program_files%xpantivirussysbackupshlwapi.dll

Navigate and Remove XP AntiVirus 2008 registry values:
HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun xp antivirus
HKEY_CURRENT_USERsoftwarexp antivirusoptions lastscan
HKEY_CURRENT_USERsoftwarexp antivirusoptions afterregisterurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions autoscanonstartup
HKEY_CURRENT_USERsoftwarexp antivirusoptions
HKEY_CURRENT_USERsoftwarexp antivirusfirstrun
HKEY_CURRENT_USERsoftwarexp antivirusoptions helpurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions labelurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions minimizetotray
HKEY_CURRENT_USERsoftwarexp antivirusoptions offsiteurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions programversion
HKEY_CURRENT_USERsoftwarexp antivirusoptions startwithwindows
HKEY_CURRENT_USERsoftwarexp antivirusoptions totalscans
HKEY_CURRENT_USERsoftwarexp antivirusoptions transactionkey
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter displayname
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter errorcontrol
HKEY_CURRENT_USERsoftwarexp antivirusoptions firstrunminimize
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 inno setup: user
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 installdate
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 installlocation
HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermenuorderstart menuprogramsxp antivirus
HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun xp antivirus
HKEY_CURRENT_USERsoftwarexp antivirusoptions autoupdate
HKEY_CURRENT_USERsoftwarexp antivirusoptions billingurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions enableantirootkit
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 urlupdateinfo
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 displayname
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 helplink
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 inno setup: app path
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 inno setup: icon group
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 inno setup: setup version
HKEY_CURRENT_USERsoftwarexp antivirusoptions firstrunurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions billingurlapproved
HKEY_CURRENT_USERsoftwaremicrosoftwindowsshellnoroammuicache c:program filesxpantivirusxpantivirus.exe
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 publisher
HKEY_CURRENT_USERsoftwarexp antivirusoptions updateurl
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter imagepath
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter start
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilter type
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilterenum
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilterenum count
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 nomodify
HKEY_CURRENT_USERsoftwarexp antivirusoptions aff
HKEY_CURRENT_USERsoftwarexp antivirusoptions registerurl
HKEY_CURRENT_USERsoftwarexp antivirusoptions startminimized
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilterenum initstartfailed
HKEY_CURRENT_USERsoftwarexp antivirusoptions enablesysbackup
HKEY_CURRENT_USERsoftwarexp antivirus
HKEY_CURRENT_USERsoftwarexp antivirusoptions checkhidden
HKEY_CURRENT_USERsoftwarexp antivirusoptions enableadvanced
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 norepair
HKEY_CURRENT_USERsoftwarexp antivirusoptions versionurl
HKEY_CURRENT_USERsoftwarexp antivirusregister
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{9a19966f-ae0e-4699-8cce-9b6f5f1c352c}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 quietuninstallstring
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 uninstallstring
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallxp antivirus_is1 urlinfoabout
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfilterenum nextinstance
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfiltersecurity
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicesxpantivirusfiltersecurity security
HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun xp antivirus

Navigate and delete XP AntiVirus 2008 files:
%program_files%xpantivirusxpantivirus.url
%program_files%xpantivirusxpantivirus_log.txt
%program_files%xpantivirusunins000.dat
xpantivirus.lnk
xpantivirus.url
%program_files%xpantivirusbackup.lst
%program_files%xpantivirushelper.sys
%program_files%xpantiviruspn.cfg
%program_files%xpantivirusver.dat
%program_files%xpantiviruswhitelist.cfg
%program_files%xpantivirusspyware.dat
%common_programs%xp antivirusuninstall xpantivirus.lnk
%common_programs%xp antivirusxpantivirus on the web.lnk
%common_programs%xp antivirusxpantivirus.lnk
%desktopdirectory%xpantivirus.lnk
%profile%application datamicrosoftinternet explorerquick launchxpantivirus.lnk
%program_files%xpantivirus
%program_files%xpantivirussysbackup
%common_programs%xp antivirus
%program_files%xpantivirusquarantine

What are the symptoms of XP AntiVirus 2008?

  • XP AntiVirus 2008 may generate fake system error messages
  • XP AntiVirus 2008 may install with other programs from unsafe webpage
  • XP AntiVirus 2008 may pop up a series of ads
  • XP AntiVirus 2008 may display false scan results and alerts
  • XP AntiVirus 2008 may decrease system performance

How do I keep away from XP AntiVirus 2008?
Once you have cleaned up XP AntiVirus 2008, the most important point to prevent XP AntiVirus 2008 and future malicious programs from reverting is to stay suspicious of spam E-mail attachment and unknown websites. Here are several ways in which you can help protect your computer against XP AntiVirus 2008 and other malware:

  • Use a computer firewall
  • Confirm that you have downloaded all the latest critical security updates
  • Adjust Internet Explorer web browser’s security settings
  • Download and install anti-spyware protection, such as, Spyware Cease
  • Surf sites and download programs from the web sites you trust

What is Rogue AntiSpyware Program?
XP AntiVirus 2008 is a type of Rogue AntiSpyware Program.

Rogue Anti-spyware Software is the software that uses malware to advise or install itself through other malicious viruses or security hole without your permission. Rogue software usually pops up fake system message such as “Warning, your computer is infected! Click here to scan your computer now!” Most of the time, when clicking the “OK” button on the dialog tab, users will be directed to an unknown website that may download more spyware threats. Sometimes, even clicking the close button on the top right may lead to the installation of the rogue software, for the button is actually a link.

With the purpose to trick innocent users into the action of paying, rogue software usually counterfeits exaggerated and fake system scanning results and scare users to pay for the removal of the never-existed spyware infections. In fact, the threat is the rogue software itself. Most of them come with a bundle of very harmful spyware programs that hidden in the files themselves.

VirusResponse Lab 2009

What is VirusResponse Lab 2009?
VirusResponse Lab 2009, also known as VirRL 2009 or VirRL2009, is an undesirable malware which may have run on your computer to invade your privacy and ruin the Internet community. VirusResponse Lab 2009 is indeed counterfeit anti-spyware software like most fake antispywares, issuing misleading and exaggerated results. VirusResponse Lab 2009 is particularly spiteful, for it merely aims to “bully” the user into purchasing their commercial version, but it never does any of what the creators claim to remove any spyware or malicious content from ones PC.

Through Vundo Trojan, Virus or fake software, VirusResponse Lab 2009 usually installed itself onto your PC without your permission. Once installation is completed on a computer, VirusResponse Lab 2009 will display fake system alerts or fake security alerts to trick user to buy its paid version to remove the potential and reported problems. This particular malware not only causes your computer to slow down apparently, but also put your privacy and data in risk.

Do you have VirusResponse Lab 2009?
If you have enough time and expertise, you can search your computer for VirusResponse Lab 2009 manually. However, it might take hours to find out all files of VirusResponse Lab 2009, and it is possible that VirusResponse Lab 2009 will appear after rebooting, for its hidden files may still be there.

Download automatic scanner for VirusResponse Lab 2009
Spyware Cease – the technology-oriented security protection that provides a risk-free computing environment for your home and office – with detection, removal and guard in one intuitive and straight-forward interface. Only Spyware Cease gives you individual fix against the most dangerous spyware problems.

Manual VirusResponse Lab 2009 removal instructions
WARNING: The manually removal method is for advanced users. VirusResponse Lab 2009 manually removal can be difficult and time-consuming. There is no guarantee that VirusResponse Lab 2009 can be completely removed, for there are hundreds of files generated when VirusResponse Lab 2009 installed on your system. Make sure to back up your computer in case that you make any mistakes and your system does not work.

Follow the instruction below for VirusResponse Lab 2009 removal manually:

Navigate and stop VirusResponse Lab 2009 processes:
ViRsLab.exe
VResLab.exe
VirRL2009.exe
VirusResponseLab2009.exe
uninst.exe
virlab_install[1].exe
VirusRL2009.exe

Navigate and Unregister VirusResponse Lab 2009 DLL Files:
VirRLWarning.dll
AVLWarning.dll
VResLabWarning.dll
ViRsLabWarning.dll

Navigate and Remove VirusResponse Lab 2009 registry values:
Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{B494E7BB-1E33-4922-A947-F74EFF4E714F}
MICROSOFT\WINDOWS\CURRENTVERSION\RUN\VResLab
Microsoft\Windows\CurrentVersion\App Paths\ViRsLab
Microsoft\Windows\CurrentVersion\Uninstall\ViRsLab
Microsoft\Windows\CurrentVersion\App Paths\VirRL2009
VirRLWarning.WarningBHO.1
VirRLWarning.WarningBHO
{A81EBFD7-0FA3-41ec-B60D-6DAE78B4D31A}
Microsoft\Windows\CurrentVersion\Run\VirRL2009
Microsoft\Windows\CurrentVersion\Uninstall\VirRL2009
Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{A81EBFD7-0FA3-41ec-B60D-6DAE78B4D31A}
Microsoft\Windows\CurrentVersion\App Paths\VResLab
VResLabWarning.WarningBHO.1
VResLabWarning.WarningBHO
VResLab
{B494E7BB-1E33-4922-A947-F74EFF4E714F}
Microsoft\Windows\CurrentVersion\Uninstall\VResLab
Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{A21C8D81-A9C7-46c6-A488-2A32FA0DAEB6}
Microsoft\Windows\CurrentVersion\Uninstall\VirusResponseLab2009
Microsoft\Windows\CurrentVersion\Run\VirusResponseLab2009
VirusResponseLab2009
AVLWarning.WarningBHO
AVLWarning.WarningBHO.1
{A21C8D81-A9C7-46c6-A488-2A32FA0DAEB6}
{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
{A8954909-1F0F-41A5-A7FA-3B376D69E226}
Microsoft\Windows\CurrentVersion\App Paths\VirusResponseLab2009
Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{0DCD4F35-9FD5-420b-A9AA-FED0E2AECEE0}
Microsoft\Windows\CurrentVersion\Uninstall\VirusRL2009
Microsoft\Windows\CurrentVersion\Run\VirusRL2009
VirusRL2009
{0DCD4F35-9FD5-420b-A9AA-FED0E2AECEE0}
{F5734812-E6A1-8833-ECA9-949B5B8A88BF}
VRLWarning.WarningBHO
VRLWarning.WarningBHO.1
Microsoft\Windows\CurrentVersion\App Paths\VirusRL2009

Navigate and delete VirusResponse Lab 2009 files:
VirRLWarning.dll
VirRL2009.exe
VirusResponseLab2009.exe
uninst.exe
AVLWarning.dll
virlab_install[1].exe
VirusRL2009.exe
VResLab.exe
VResLabWarning.dll
ViRsLab.exe
ViRsLabWarning.dll

What are the symptoms of VirusResponse Lab 2009?

  • VirusResponse Lab 2009 may invade one’s privacy and ruin the Internet community
  • VirusResponse Lab 2009 may issue misleading and exaggerated results
  • VirusResponse Lab 2009 may install through Vundo Trojan, Virus or fake software without permission
  • VirusResponse Lab 2009 display fake system alerts or fake security alerts
  • VirusResponse Lab 2009 may cause computer to slow down apparently

How do I keep away from VirusResponse Lab 2009?
Once you have cleaned up VirusResponse Lab 2009, the most important point to prevent VirusResponse Lab 2009 and future malicious programs from reverting is to stay suspicious of spam E-mail attachment and unknown websites. Here are several ways in which you can help protect your computer against VirusResponse Lab 2009 and other malware:

  • Use a computer firewall
  • Confirm that you have downloaded all the latest critical security updates
  • Adjust Internet Explorer web browser’s security settings
  • Download and install anti-spyware protection, such as, Spyware Cease
  • Surf sites and download programs from the web sites you trust

What is Rogue AntiSpyware Program?
VirusResponse Lab 2009 is a type of Rogue AntiSpyware Program.

Rogue Anti-spyware Software is the software that uses malware to advise or install itself through other malicious viruses or security hole without your permission. Rogue software usually pops up fake system message such as “Warning, your computer is infected! Click here to scan your computer now!” Most of the time, when clicking the “OK” button on the dialog tab, users will be directed to an unknown website that may download more spyware threats. Sometimes, even clicking the close button on the top right may lead to the installation of the rogue software, for the button is actually a link.

With the purpose to trick innocent users into the action of paying, rogue software usually counterfeits exaggerated and fake system scanning results and scare users to pay for the removal of the never-existed spyware infections. In fact, the threat is the rogue software itself. Most of them come with a bundle of very harmful spyware programs that hidden in the files themselves.