<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title><![CDATA[Spyware Removal, Security &amp; Privacy Blog]]></title>
      <link>http://www.2-freespywareremoval.com/Remove-Spyware/</link>
      <description></description>
      <language>en</language>
      <copyright>Copyright 2006</copyright>
      <lastBuildDate>Mon, 18 Dec 2006 10:49:03 -0500</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=3.2</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>AntiVermins Removal - How to Remove AntiVermins</title>
         <description><![CDATA[<p>AntiVermins is an anti-spyware program that secretly installs a trojan onto your computer and displays false security notifications in attempt to get you to buy their software.</p>

<p>You may be infected with AntiVermins, if you detect <b>C:\Program Files\AntiVermins\AntiVermins.exe</b> on your computer. </p>

<p><u><b>Remove AntiVermins</b></u><br />
Choose AntiVermins removal procedure:</p>

<p>- AntiVermins Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- AntiVermins Manual Removal, <a href="#razespyware_manual_removal">click here.</a> (Some technical skills required.)<br />
<br/><br />
<b>AntiVermins Image</b></p>

<p><img alt="antivermins-image.jpg" src="/Remove-Spyware/antivermins.png" width="580" height="375" /><br />
<br/><br />
<u><b><a name="antivermins_manual_removal">AntiVermins Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove AntiVermins.  </p>

<p><b>Detect and remove these AntiVermins processes:</b><br />
AntiVerminsPro.exe<br />
av_setup_v2_1[1].exe<br />
antivermins.exe</p>

<p><b>Delete these AntiVermins DLL files:</b><br />
msvcp71.dll<br />
msvcr71.dll<br />
hjpprpu.dll<br />
cvnzie.dll<br />
kuhmk.dll</p>

<p><b>Remove these AntiVermins registry values:</b><br />
HKEY_CLASSES_ROOT\clsid\{663de629-4ffd-a944-6f0a-64f98e925b62} <br />
HKEY_CLASSES_ROOT\interface\{0be87caf-1c8e-43c7-a476-5af1a2f5a43f} <br />
HKEY_CLASSES_ROOT\interface\{0cd726ec-f1f5-4210-9011-ee6b5332a279} <br />
HKEY_CLASSES_ROOT\interface\{1efd4366-6676-4af7-a88a-872a49e2601d} <br />
HKEY_CLASSES_ROOT\interface\{3b3fa480-138e-47e6-b79a-9a0f7b2846d5} <br />
HKEY_CLASSES_ROOT\interface\{3e186ce2-1abb-45d6-a4b9-4fcd11fbb014} <br />
HKEY_CLASSES_ROOT\interface\{4af8e04f-0d5e-4c3f-ba67-81b685584c12} <br />
HKEY_CLASSES_ROOT\interface\{6c80c5b2-4748-411c-8120-09426f8ed212} <br />
HKEY_CLASSES_ROOT\interface\{748c9204-6c92-485b-8bf8-3af7ecf03cde} <br />
HKEY_CLASSES_ROOT\interface\{b6a0aa8a-7cb1-44f0-ace7-7a69739c8674} <br />
HKEY_CLASSES_ROOT\interface\{c27d97e9-004b-4f4f-a5b0-b7188ddae024} <br />
HKEY_CLASSES_ROOT\interface\{c3176a2c-3119-4f7f-b847-62b5ee6763e5} <br />
HKEY_CLASSES_ROOT\interface\{cac16e1a-d86b-428a-bb7b-65f2d2bfc160} <br />
HKEY_CLASSES_ROOT\interface\{dd369501-ede4-4e99-8728-7c9e4bbe6be8} <br />
HKEY_CLASSES_ROOT\interface\{eac1accd-7790-4991-a9d2-550806d6d9c3} <br />
HKEY_CLASSES_ROOT\interface\{ef2aa606-b72e-4a1b-b076-8b148661f3b7} <br />
HKEY_CLASSES_ROOT\interface\{f9476885-40eb-4405-878a-193baf18ce9b} <br />
HKEY_CLASSES_ROOT\typelib\{13693777-5b9d-4afc-99f1-650f569a0eb0} <br />
HKEY_LOCAL_MACHINE\software\antivermins <br />
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\antivermins.exe <br />
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run antivermins <br />
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\antivermins</p>

<p><br />
<b>Detect and remove these AntiVermins files:</b><br />
AntiVerminsPro 2.1.lnk<br />
AntiVerminsPro.lnk<br />
AntiVerminsPro 2.1 Website.lnk<br />
Uninstall AntiVerminsPro 2.1.lnk</p>

<p><br />
External Links:<br />
<a href="http://en.wikipedia.org/wiki/Spyware">http://en.wikipedia.org/wiki/Spyware</a><br />
<a href="http://www.antispywarecoalition.org">http://www.antispywarecoalition.org</a></p></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/12/antivermins_removal_how_to_rem.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/12/antivermins_removal_how_to_rem.php</guid>
         <category>AntiVermins</category>
         <pubDate>Mon, 18 Dec 2006 10:49:03 -0500</pubDate>
      </item>
            <item>
         <title>Mirar Removal - How to Remove Mirar</title>
         <description><![CDATA[<p>Mirar is a Browser Helper Object (BHO) that adds to the web browser as an Internet Explorer toolbar. Mirar creates targeted pop-up ads based on visited URLs and search terms used. While you surf the web, Mirar Toolbar collects data in an attempt to display affiliate Web pages that are related to the Web page currently being viewed. Mirar is also known as GetMirar, www.getmirar.com. This program is currently offering an uninstaller.</p>

<p>You may be infected with Mirar, if you detect <b>C:\Windows\mirar\mirarsetup.exe.</b> on your computer. </p>

<p><u><b>Remove Mirar</b></u><br />
Choose Mirar removal procedure:</p>

<p>- <a href="/FreeSpywareScanner.exe">Mirar Automatic Removal</a> (Fast &amp; Easy.) </p>

<p>- <a href="#mirar_manual_removal">Mirar Manual Removal</a> (Some technical skills required.)</p>

<p><b>Mirar Image</b></p>

<p><img alt="mirar image" src="/Remove-Spyware/mirar.gif" width="600" height="31" /></p>

<p><u><b><a name="mirar_manual_removal">Mirar Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe">automatic check</a> to detect and remove Mirar.  </p>

<p><b>Detect and delete these Mirar processes:</b><br />
mirarsetup.exe<br />
875455-NOSB.exe </p>

<p><b>Remove these Mirar DLL files:</b><br />
winnb[X].dll<br />
winnb40.dll<br />
winnb41.dll<br />
windmy.dll<br />
nn_bar.dll<br />
nn_bar21.dll<br />
nn_bar22.dll<br />
nn_bar31.dll</p>

<p><b>Remove these Mirar registry values:</b><br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunToolbarInstall=mirarsetup.exe<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLsC:WindowsDownloadedProgramFilesmirarsetup.exe<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLsC:WindowsSystem32windmy.dll<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/Windows/DownloadedProgramFiles/mirarsetup.exe<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/Windows/System32/windmy.dll<br />
9A9C9B68-F908-4AAB-8D0C-10EA8997F37E<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar.NN_Bar_Helper<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar.NN_Bar_Helper.1<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar.NN_WebBand<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar.NN_WebBand.1<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar_Dummy.NN_BarDummy<br />
HKEY_LOCAL_MACHINESOFTWAREClassesNN_Bar_Dummy.NN_BarDummy.1<br />
179E4B4A-76C3-4F65-BCED-C9FA1A28D2EF<br />
8A0DCBDA-6E20-489C-9041-C1E8A0352E75<br />
1037B06C-84B7-4240-8D80-485810A0497D<br />
224302B0-94E9-45C2-9E5B-BA989EE556E1<br />
54B287F9-FD90-4457-B65E-CB91560C021D<br />
6E4C7AFC-9915-4036-B7F9-8B3F1710788F<br />
566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49<br />
F8310E7D-4C4D-46A4-A068-B5BB99411CC7<br />
4035DE1B-D54A-411E-9EE7-923295D2E86E<br />
753B9349-7E46-4E5C-A27F-A60A6BF1EAB5<br />
9A9C9B69-F908-4AAB-8D0C-10EA8997F37E<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternetSettingsoneMapDomains<br />
et-nucleus.com</p>

<p><b>Detect and remove these Mirar files:</b><br />
mit3.tmp <br />
mit3.tmp.cab</p>

<p><b>Mirar Variants:</b><br />
Mirar Virus, Mirar Spyware, <br />
Mirar Adware, Mirar Toolbar, <br />
Mirar Tolbar, Mirar Tool Bar, <br />
Adware.Mirar, GetMirar.<br />
</p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/08/mirar_removal_how_to_remove_mi.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/08/mirar_removal_how_to_remove_mi.php</guid>
         <category>Mirar</category>
         <pubDate>Mon, 07 Aug 2006 15:00:41 -0500</pubDate>
      </item>
            <item>
         <title>SpyHeal Removal - How to Remove SpyHeal</title>
         <description><![CDATA[<p>SpyHeal, the latest version of <a href="/Remove-Spyware/2006/05/spywarequake_removal_how_to_re_1.php" title="SpywareQuake Removal">SpywareQuake</a>, is a rogue anti-spyware program that secretly installs a trojan onto your computer and pops up false security notifications in attempt to get you to buy the SpyHeal software.</p>

<p>You may be infected with Spy Heal, if you detect <b>C:\Windows\spyheal\spyheal.exe.</b> on your computer. </p>

<p><u><b>Remove Spy Heal</b></u><br />
Choose Spy Heal removal procedure:</p>

<p>- <a href="/FreeSpywareScanner.exe">SpyHeal Automatic Removal</a> (Fast &amp; Easy.) </p>

<p>- <a href="#spyheal_manual_removal">SpyHeal Manual Removal</a> (Some technical skills required.)</p>

<p><b>SpyHeal Image</b></p>

<p><img alt="spyheal image" src="/Remove-Spyware/spyheal.jpg" width="648" height="439" /></p>

<p><u><b><a name="spyheal_manual_removal">SpyHeal Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe">automatic check</a> to detect and remove SpyHeal.  </p>

<p><b>Detect and delete these Spy Heal processes:</b><br />
spyheal_setup.exe <br />
spyheal.exe <br />
uninst.exe  </p>

<p><b>Remove these SpyHeal DLL files:</b><br />
msvcp71.dll <br />
msvcr71.dll</p>

<p><b>Remove these Spy Heal registry values:</b><br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpywareQuake <br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ <br />
CurrentVersion\Uninstall\SpywareQuake\UninstallString: "%programfiles%\SpywareQuake\uninst.exe" <br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ <br />
CurrentVersion\Uninstall\SpywareQuake\URLInfoAbout: "http://www.spywarequake.com" <br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ <br />
CurrentVersion\Uninstall\SpywareQuake\Publisher: "SpywareQuake.com"</p>

<p><b>Detect and remove these SpyHeal files:</b><br />
uninstall spyheal 2.1.lnk <br />
spyheal.lnk <br />
spyheal 2.1 website.lnk <br />
spyheal 2.1.lnk <br />
blacklist.txt <br />
english.ini <br />
spyheal.url <br />
ref.dat <br />
ref.dat.old</p>

<p><b>SpyHeal Variants:</b><br />
spyheal 2.0 , spy heal 2.0 <br />
spyheal 2.1 , spy heal 2.1<br />
spyheal v.2.1 , spy heal v.2.1<br />
spyheal v2.1 , spy heal v2.1<br />
spyheal spywarequake<br />
spyheal trojan</p>

<p><br />
<br><p>External Links:<br />
<a href="http://en.wikipedia.org/wiki/Spyware">http://en.wikipedia.org/wiki/Spyware</a><br />
<a href="http://www.antispywarecoalition.org">http://www.antispywarecoalition.org</a></p></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/07/spyheal_removal_how_to_remove.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/07/spyheal_removal_how_to_remove.php</guid>
         <category>SpyHeal</category>
         <pubDate>Wed, 26 Jul 2006 11:49:14 -0500</pubDate>
      </item>
            <item>
         <title>WinFixer Removal - How to Remove WinFixer</title>
         <description><![CDATA[<p>WinFixer, also known as Virtumonde, is a registry cleaner which pretends to scan and fix registry problems, repair files and hard drive errors. WinFixer may install adware and other programs without your consent. WinFixer can be installed upon visiting www.600pics.com. WinFixer may display pop-ups and uncloseable message boxes. Similar WinFixer programs are ErrorSafe, WinSoftware, and GasBuddies.</p>

<p>You may be infected with WinFixer, if you detect <b>C:\Windows\winfixer\winfixer20.exe.</b> on your computer. </p>

<p><u><b>Remove WinFixer</b></u><br />
Choose WinFixer removal procedure:</p>

<p>- <a href="/FreeSpywareScanner.exe">WinFixer Automatic Removal</a> (Fast &amp; Easy.) </p>

<p>- <a href="#winfixer_manual_removal">WinFixer Manual Removal</a> (Some technical skills required.)</p>

<p><br />
<b>WinFixer Image</b></p>

<p><img alt="winfixer 2005 image" src="/Remove-Spyware/winfixer-2005.gif" width="587" height="435" /></p>

<p><br />
<u><b><a name="winfixer_manual_removal">WinFixer Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe">automatic check</a> to detect and remove WinFixer.  </p>

<p><b>Detect and delete these WinFixer processes:</b><br />
winfixer2005setup.exe<br />
winfixer20.exe<br />
winfixerscannerinstall.exe<br />
uwfx5lp_0001_0803netinstaller.exe<br />
uwfx51.exe<br />
setup.exe<br />
df_kme.exe<br />
install.exe<br />
sr.exe<br />
updater.exe<br />
unins000.exe<br />
wfx5.exe</p>

<p><b>Remove these WinFixer DLL files:</b><br />
ffwraper.dll<br />
fixcore.dll<br />
ftrec.dll<br />
idletrac.dll<br />
mmfix.dll<br />
oedrop.dll<br />
strres.dll<br />
crxml.dll<br />
pcheck.dll<br />
compcln.dll<br />
df_fixer.dll<br />
df_proxy.dll<br />
ffcom.dll</p>

<p><b>Remove these WinFixer registry values:</b><br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settings<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingsfirstrun<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingsinstalldate<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingslast_scan_high<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingslast_scan_low<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingslast_timeout_high<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingslast_timeout_low<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingslastscanerrorcount<br />
HKEY_CURRENT_USER\software\winsoftware\winfixer2005\settingsoverwriteandbackupfilestopath<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWinFixer2005<br />
HKEY_LOCAL_MACHINE\software\winsoftware\winfixer2005abbr<br />
HKEY_LOCAL_MACHINE\software\winsoftware\winfixer2005activationcode<br />
HKEY_LOCAL_MACHINE\software\winsoftware\winfixer2005euluwfx5lp_0001_0803<br />
HKEY_LOCAL_MACHINE\software\winsoftware\winfixer2005installpath<br />
HKEY_LOCAL_MACHINE\software\winsoftware\winfixer2005productcode</p>

<p><b>Detect and remove these WinFixer files:</b><br />
unins000.dat<br />
up.datdatabase.sav<br />
program.sav<br />
license.rtf<br />
sr.log<br />
trace.log<br />
update.log<br />
support.url<br />
wfx5.url<br />
template.dbx<br />
df_kmd.sys<br />
flash.ini<br />
updater.dat<br />
activate.dat<br />
bnlink.dat<br />
lapv.dat<br />
lock.dat<br />
pv.dat</p>

<p><b>WinFixer Variants:</b><br />
Win Fixer, WinFixer 2005, <br />
Win Fixer 2005, WinFixer 2006, <br />
Win Fixer 2006, WinFixer Virus, <br />
Win Fixer Virus, WinFixer Spyware, <br />
Win Fixer Spyware, Downloader.WinFixer2006, <br />
WinFixer Adware. <br />
</p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/07/winfixer_removal_how_to_remove_1.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/07/winfixer_removal_how_to_remove_1.php</guid>
         <category></category>
         <pubDate>Tue, 25 Jul 2006 10:30:47 -0500</pubDate>
      </item>
            <item>
         <title>Top Rogue Anti-Spyware Programs</title>
         <description><![CDATA[<p>For those who are not aware of rogue antispyware or can't tell the difference between a trustworthy anti-spyware and a rogue anti-spyware, here's a little quick explanation on the matter. </p>

<p>Rogue anti-spyware programs are security tools that use fake warnings only to trick the user into believing that their computer may be infected with spyware so they are convinced to purchase the full version of rogue program. Instead of providing a spyware solution it causes more harm than good. It may take control of your computer and start issuing more popups and changing your browser default settings.</p>

<p>Here is a list of <b>popular rogue anti-spyware and security applications.</b> (Note: This spyware list will change as new spyware is detected so you will be up-to-date on what to avoid.)</p>

<p><b>SpywareQuake</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarequake_removal_how_to_re_1.php">(removal instructions)</a><br />
Spyware Quake is a trojan that displays an icon in the system tray. SpywareQuake looks like a legitimate application for removal of spyware, but it's installed by a trojan in an attempt to trick you into buying it. The trojan is able to change the Internet Explorer default home page and redirect the web browser to malicious web sites. SpywareQuake will also pop-up fake alerts that resemble system alerts in another attempt to get you to buy it.</p>

<p><b>SpyFalcon</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spyfalcon_removal_how_to_remov.php">(removal instructions)</a><br />
SpyFalcon may appear as an icon in your Windows tray and show a message that says your PC is infected with malware. SpyFalcon may then suggest you download and install software to remove this malware. If you follow its directions, you will download SpyFalcon, and once downloaded SpyFalcon may redirect your Internet Explorer home page and search results to a malicious website. SpyFalcon may also download and install other software without your permission. SpyFalcon may be distributed through bundles of trojans and other malware.</p>

<p><b>SpySheriff</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spysheriff_removal_how_to_remo.php">(removal instructions)</a><br />
SpySheriff is a system hijacker that secretly installs to victim PCs. SpySheriff causes the desktop to change and display a fake warning message that tricks users into installing the antispyware software (SpySheriff). </p>

<p><b>SpyAxe</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spyaxe_removal_how_to_remove_s.php">(removal instructions)</a><br />
SpyAxe is a trojan, that shows one or two icons in the system tray and displays a message saying that the system is infected with spyware and asking the user to download and install an anti-spyware program, which is actually a malicious software program. Once the user clicks on such message, the trojan opens the anti-spyware's official web site. It may also try to download the application automatically. SpyAxe may also change the desktop background. </p>

<p><b>PestTrap</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/pesttrap_removal_how_to_remove.php">(removal instructions)</a><br />
Pest Trap may note harmless software as threats in an attempt to have you purchase Pest Trap's full version to remove these harmless programs. PestTrap may also automatically launch at your computer's startup and scan your computer. Pest Trap may be knowingly downloaded and installed by users, and it may be installed without permission through browser exploits.</p>

<p><b>WinFixer</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winfixer_removal_how_to_remove.php">(removal instructions)</a><br />
WinFixer is a commercial product that pretends to be a legitimate system tool. WinFixer is actually spyware, which continuously displays annoying false reports of purportedly detected system problems, errors and parasite threats. This may trick the user into thinking that the program is not a security threat and make the user purchase a version of WinFixer.</p>

<p><b>BraveSentry</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/bravesentry_removal_how_to_rem.php">(removal instructions)</a><br />
BraveSentry hijacks the web browser and it is known to issue fake warnings on your computer in order to manipulate you into buying its full commercial version. It can also be installed from the BraveSentry website and has been forced onto the computer without EULA and users knownledge of installation. It does not actually detect parasites, but targets harmless system and software objects as threats in attempt to trick the user into purchasing the full version of Brave Sentry. BraveSentry is related to SpySheriff and Spware-no. </p>

<p><b>WinHound</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winhound_removal_how_to_remove_1.php">(removal instructions)</a><br />
WinHound is a trojan, which silently installs itself to vulnerable computers by exploiting certain system or web browser security flaws. Once executed, WinHound installs several other dangerous threats, changes the Internet Explorer default home page and the desktop wallpaper. The new wallpaper issues fake warnings on your computer in order to make the user to buy it's version. WinHound can use a rootkit to cloak its files, running processes and other related objects.</p>

<p><b>SpywareStrike</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarestrike_removal_how_to_r_1.php">(removal instructions)</a><br />
SpywareStrike is a variant of SpyAxe. SpywareStrike shows a message, which says that the compromised PC is infected with dangerous malware spywares and asks the user to download and install an anti-malware application, which actually is SpywareStrike, corrupt illegaly distributed malware remover. Once the user clicks on such message, the trojan opens the official web site of SpywareStrike. It may also try to download the software. The trojan is able to change the Internet Explorer default home page and send the web browser to malicious web sites. SpywareStrike automatically runs on every Windows startup. </p>

<p><b>RazeSpyware</b> <a href="http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/razespyware_removal_how_to_rem.php">(removal instructions)</a><br />
RazeSpyware claims to clean spyware after the product is registered when in reality it only searches for known threats (which signatures are included into the program's spyware definitions database) and does not check all the files, registry entries and running processes. Upon execution the Trojan adds a HTML page in %windir% as index.html (also detected as Raze Trojan). The HTML page is then installed as desktop wallpaper that displays a fake warning that system is infected with spyware, keyloggers and adult content. It prompts user to download Raze AntiSpyware to protect themselves against these threats.  </p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/06/top_rogue_antispyware_programs.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/06/top_rogue_antispyware_programs.php</guid>
         <category>Rogue Anti-Spyware</category>
         <pubDate>Thu, 01 Jun 2006 09:45:40 -0500</pubDate>
      </item>
            <item>
         <title>Recent SpyFalcon file detected, oqipt.dll.</title>
         <description><![CDATA[<p>SpyFalcon, a rogue anti-spyware program, displays fake security warnings claiming that your PC is infected with malicious spyware tricking users into purchasing their software. Now there's a new SpyFalcon variant released, <b>C:\Windows\System32\oqipt.dll.</b> If you have <b>oqipt.dll</b> on your computer, you may be infected with SpywareQuake.</p>

<p><a href="/FreeSpywareScanner.exe">Remove SpyFalcon</a> and it's variant oqipt.dll automatically -- <a href="/FreeSpywareScanner.exe">click here</a> (Fast &amp; Easy). </p>

<p>Manually remove <b>oqipt.dll</b> from the following registry keys:<br />
<font size="1"><b>Note:</b> Manual removal can be dangerous. Avoid damaging your machine, <a href="/FreeSpywareScanner.exe">scan your computer</a> for SpywareQuake. </font></p>

<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
SharedTaskScheduler]<br />
“{5bc82bdb-bc03-4671-9a78-3ef2b68449de}”=”advisability”</p>

<p>[HKEY_CURRENT_USER\Software\Classes\CLSID\<br />
{5bc82bdb-bc03-4671-9a78-3ef2b68449de}\InProcServer32]<br />
@=”C:\WINDOWS\system32\<font color="#FF0000">oqipt.dll</font>"</p>

<p>SpyFalcon manual removal instructions available, <a href="/Remove-Spyware/2006/05/spyfalcon_removal_how_to_remov.php">click here.</a></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spyfalcon_file_detected_oq.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spyfalcon_file_detected_oq.php</guid>
         <category>SpyFalcon</category>
         <pubDate>Mon, 22 May 2006 09:28:23 -0500</pubDate>
      </item>
            <item>
         <title>SpyFalcon variant detected - appmagr.dll</title>
         <description><![CDATA[<p>SpyFalcon, a rogue anti-spyware program, displays fake security warnings claiming that your PC is infected with malicious spyware tricking users into purchasing their software. Now there's a new SpyFalcon variant released, <b>C:\Windows\System32\appmagr.dll.</b> If you have <b>appmagr.dll</b> on your computer, you may be infected with SpywareQuake.</p>

<p><a href="/FreeSpywareScanner.exe">Remove SpyFalcon</a> and it's variant appmagr.dll automatically -- <a href="/FreeSpywareScanner.exe">click here</a> (Fast &amp; Easy). </p>

<p>Manually remove <b>appmagr.dll</b> from the following registry keys:<br />
<font size="1"><b>Note:</b> Manual removal can be dangerous. Avoid damaging your machine, <a href="/FreeSpywareScanner.exe">scan your computer</a> for SpywareQuake. </font></p>

<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
SharedTaskScheduler]<br />
“{64ba30a2-811a-4597-b0af-d551128be340}”=”AppManager”</p>

<p>[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\<br />
{64ba30a2-811a-4597-b0af-d551128be340}\InProcServer32]<br />
@=”C:\WINDOWS\system32\<font color="#FF0000">appmagr.dll</font>"</p>

<p>SpyFalcon manual removal instructions available, <a href="/Remove-Spyware/2006/05/spyfalcon_removal_how_to_remov.php">click here.</a></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spyfalcon_file_appmagrdll.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spyfalcon_file_appmagrdll.php</guid>
         <category>SpyFalcon</category>
         <pubDate>Sun, 21 May 2006 09:27:16 -0500</pubDate>
      </item>
            <item>
         <title>New SpyFalcon File - sbnudh.dll</title>
         <description><![CDATA[<p>SpyFalcon, a rogue anti-spyware program, displays fake security warnings claiming that your PC is infected with malicious spyware tricking users into purchasing their software. Now there's a new SpyFalcon variant released, <b>C:\Windows\System32\sbnudh.dll.</b> If you have <b>sbnudh.dll</b> on your computer, you may be infected with SpywareQuake.</p>

<p><a href="/FreeSpywareScanner.exe">Remove SpyFalcon</a> and it's variant sbnudh.dll automatically -- <a href="/FreeSpywareScanner.exe">click here</a> (Fast &amp; Easy). </p>

<p>Manually remove <b>sbnudh.dll</b> from the following registry keys:<br />
<font size="1"><b>Note:</b> Manual removal can be dangerous. Avoid damaging your machine, <a href="/FreeSpywareScanner.exe">scan your computer</a> for SpywareQuake. </font></p>

<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
SharedTaskScheduler]<br />
“{89aef01d-d237-49c7-84dc-4e1904c1fd31}”=”AutoDisc Ware”</p>

<p>[HKEY_CURRENT_USER\Software\Classes\CLSID\<br />
{89aef01d-d237-49c7-84dc-4e1904c1fd31}\InProcServer32]<br />
@=”C:\WINDOWS\system32\<font color="#FF0000">sbnudh.dll</font>"</p>

<p>SpyFalcon manual removal instructions available, <a href="/Remove-Spyware/2006/05/spyfalcon_removal_how_to_remov.php">click here.</a></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/post.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/post.php</guid>
         <category>SpyFalcon</category>
         <pubDate>Sat, 20 May 2006 09:23:07 -0500</pubDate>
      </item>
            <item>
         <title>RazeSpyware Removal - How to Remove RazeSpyware</title>
         <description><![CDATA[<p>RazeSpyware is an anti-spyware program that secretly installs a trojan onto your computer and displays false security notifications in attempt to get you to buy their software.</p>

<p>You may be infected with Raze Spyware, if you detect <b>C:\Program Files\RazeSpyware\RazeSpyware.exe</b> on your computer. </p>

<p><u><b>Remove RazeSpyware</b></u><br />
Choose RazeSpyware removal procedure:</p>

<p>- RazeSpyware Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- RazeSpyware Manual Removal, <a href="#razespyware_manual_removal">click here.</a> (Some technical skills required.)<br />
<br/><br />
<b>Raze Spyware Image</b></p>

<p><img alt="razespyware-image.jpg" src="/Remove-Spyware/razespyware.jpg" width="590" height="311" /><br />
<br/><br />
<u><b><a name="razespyware_manual_removal">Raze Spyware Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove RazeSpyware.  </p>

<p><b>Detect and remove these RazeSpyware processes:</b><br />
razespyware.exe <br />
razespyware_monitor.exe <br />
uninstall.exe </p>

<p><b>Delete these RazeSpyware DLL files:</b><br />
razespyware.dll <br />
razespyware_monitor.dll <br />
unzdll.dll <br />
mswinb32.dll <br />
mswinf32.dll </p>

<p><b>Remove these Raze Spyware registry values:</b><br />
HKEY_CLASSES_ROOT\winapi32.MyBHO <br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper </p>

<p>Objects\{7A533235-A128-434B-9F8A-9300A544D191} <br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ RazeSpyware <br />
HKEY_USERS\*\Software\ RazeSpyware</p>

<p><b>Detect and remove these RazeSpyware files:</b><br />
razespyware.lnk <br />
autoexec.sss</p>

<p></p>

<p><br><p>External Links:<br />
<a href="http://en.wikipedia.org/wiki/Spyware">http://en.wikipedia.org/wiki/Spyware</a><br />
<a href="http://www.antispywarecoalition.org">http://www.antispywarecoalition.org</a></p></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/razespyware_removal_how_to_rem.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/razespyware_removal_how_to_rem.php</guid>
         <category>RazeSpyware</category>
         <pubDate>Mon, 15 May 2006 10:21:29 -0500</pubDate>
      </item>
            <item>
         <title>SpywareStrike Removal - How to Remove SpywareStrike</title>
         <description><![CDATA[<p>SpywareStrike is an anti-spyware program that secretly installs a trojan onto your computer and displays false security notifications in attempt to get you to buy their software.</p>

<p>You may be infected with SpywareStrike, if you detect <b>C:\Program Files\SpywareStrike\SpywareStrike.exe</b> on your computer. </p>

<p><u><b>Remove SpywareStrike</b></u><br />
Choose SpySheriff removal procedure:</p>

<p>- SpywareStrike Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- SpywareStrike Manual Removal, <a href="#spywarestrike_manual_removal">click here.</a> (Some technical skills required.)<br />
<br/><br />
<b>SpywareStrike Image</b></p>

<p><img alt="spywarestrike-image.jpg" src="/Remove-Spyware/spywarestrike-image.jpg" width="500" height="372" /><br />
<br/><br />
<u><b><a name="spywarestrike_manual_removal">SpyAxe Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove SpywareStrike.  </p>

<p><b>Detect and remove these SpywareStrike processes:</b><br />
spywarestrike.exe<br />
ss_setup.exe</p>

<p><b>Delete these SpywareStrike DLL files:</b><br />
netwrap.dll<br />
replmap.dll<br />
wiatwain.dll  </p>

<p><b>Remove these SpywareStrike registry values:</b><br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunSpywareStrike <br />
HKEY_LOCAL_MACHINE SOFTWAREClassesAppID{70F17C8C-1744-41B6-9D07-575DB448DCC5} <br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionApp Pathsspywarestrike.exe <br />
HKEY_LOCAL_MACHINE SOFTWARESpywareStrike </p>

<p><b>Detect and remove these SpywareStrike files:</b><br />
nvctrl.exe<br />
hp[X].tmp</p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarestrike_removal_how_to_r_1.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarestrike_removal_how_to_r_1.php</guid>
         <category>SpywareStrike</category>
         <pubDate>Mon, 15 May 2006 10:19:32 -0500</pubDate>
      </item>
            <item>
         <title>SpywareQuake - New SpyQuake File xenadot.dll</title>
         <description><![CDATA[<p>SpywareQuake, a rogue anti-spyware program, displays fake security warnings claiming that your PC is infected with malicious spyware tricking users into purchasing their software. Now there's a new SpywareQuake variant released, <b>C:\Windows\System32\xenadot.dll.</b>  If you have <b>xenadot.dll</b> on your computer, you may be infected with SpywareQuake.</p>

<p><a href="/FreeSpywareScanner.exe">Remove SpywareQuake</a> and it's variant xenadot.dll automatically -- <a href="/FreeSpywareScanner.exe">click here</a> (Fast &amp; Easy). </p>

<p>Manually remove <b>xenadot.dll</b> from the following registry keys:<br />
<font size="1"><b>Note:</b> Manual removal can be dangerous. Avoid damaging your machine, <a href="/FreeSpywareScanner.exe">scan your computer</a> for SpywareQuake.</font></p>

<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
SharedTaskScheduler]<br />
“{CD5E2AC9-25CE-A1C5-D1E2-DC6B28A6ED5A}”=”XenaDot Software”</p>

<p>[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\<br />
{CD5E2AC9-25CE-A1C5-D1E2-DC6B28A6ED5A}\InProcServer32]<br />
@=”C:\WINDOWS\system32\<font color="#FF0000">xenadot.dll</font>"</p>

<p>SpywareQuake manual removal instructions available, <a href="/Remove-Spyware/2006/05/spywarequake_removal_how_to_re_1.php">click here.</a></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarequake_new_spyquake_file.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/spywarequake_new_spyquake_file.php</guid>
         <category>SpywareQuake</category>
         <pubDate>Sun, 14 May 2006 09:20:01 -0500</pubDate>
      </item>
            <item>
         <title>WinHound Removal - How to Remove WinHound</title>
         <description><![CDATA[<p>WinHound is an anti-spyware program that secretly installs a trojan onto your computer and displays false security <br />
notifications in attempt to get you to buy their software.</p>

<p>You may be infected with WinHound, if you detect <b>C:\Program Files\WinHound\WinHound.exe</b> on your computer. </p>

<p><u><b>Remove WinHound</b></u><br />
Choose SpySheriff removal procedure:</p>

<p>- WinHound Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- WinHound Manual Removal, <a href="#winhound_manual_removal">click here.</a> (Some technical skills required.)</p>

<p><b>WinHound Image</b></p>

<p><img alt="winhound-image.jpg" src="/Remove-Spyware/winhound2.jpg" width="428" height="353" /></p>

<p><br />
<u><b><a name="winhound_manual_removal">SpyAxe Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove WinHound.  </p>

<p><b>Detect and remove these WinHound processes:</b><br />
winhound.exe<br />
winhoundinstaller.exe<br />
uninstall.exe</p>

<p><b>Delete these WinHound DLL files:</b><br />
mtc.dll<br />
oleext.dll<br />
shdochp.dll</p>

<p><b>Remove these WinHound registry values:</b><br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWinHound <br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows </p>

<p>CurrentVersionShellServiceObjectDelayLoad{F33812FB-F35C-4674-90F6-FD757C419C51} <br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftShared ToolsMSConfigstartupreglinks <br />
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftShared ToolsMSConfigstartupregWinHound <br />
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainStart Page=[local address] </p>

<p><b>Detect and remove these WinHound files:</b><br />
uninstall.lnk<br />
start winhound spyware<br />
remover.lnk<br />
register winhound spyware</p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winhound_removal_how_to_remove_1.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winhound_removal_how_to_remove_1.php</guid>
         <category>WinHound</category>
         <pubDate>Sat, 13 May 2006 10:15:56 -0500</pubDate>
      </item>
            <item>
         <title>BraveSentry Removal - How to Remove BraveSentry</title>
         <description><![CDATA[<p>BraveSentry is an anti-spyware program that secretly installs a trojan onto your computer and displays false security notifications in attempt to get you to buy their software.</p>

<p>You may be infected with BraveSentry, if you detect <b>C:\Program Files\BraveSentry\BraveSentry.exe</b> on your computer. </p>

<p><u><b>Remove BraveSentry</b></u><br />
Choose BraveSentry removal procedure:</p>

<p>- Brave Sentry Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- BraveSentry Manual Removal, <a href="#bravesentry_manual_removal">click here.</a> (Some technical skills required.)</p>

<p><b>Brave Sentry Image</b></p>

<p><img alt="bravesentry-image.gif" src="/Remove-Spyware/bravesentry.gif" width="394" height="345" /><br />
<br/><br />
<u><b><a name="bravesentry_manual_removal">BraveSentry Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove BraveSentry.  </p>

<p><b>Detect and remove these Brave Sentry processes:</b><br />
bravesentry.exe<br />
vxgamet[X2].exe<br />
vxh8jkdq[X2].exe</p>

<p><b>Delete these BraveSentry DLL files:</b><br />
bravesentry0.dll<br />
bravesentry1.dll<br />
bravesentry2.dll<br />
bravesentry3.dll</p>

<p><b>Detect and remove these BraveSentry files:</b><br />
maxd64.exe<br />
services.exe<br />
taskdir.exe</p>

<p><br />
<b>BraveSentry Variants:</b><br />
BraveSentry 2.0 , Brave Sentry 2.0 <br />
BraveSentry 2 , BraveSentry 2</p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/bravesentry_removal_how_to_rem.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/bravesentry_removal_how_to_rem.php</guid>
         <category>BraveSentry</category>
         <pubDate>Fri, 12 May 2006 10:15:08 -0500</pubDate>
      </item>
            <item>
         <title>New Spy Quake Variant, dvdcap.dll</title>
         <description><![CDATA[<p>SpywareQuake, a rogue anti-spyware program, displays fake security warnings claiming that your PC is infected with malicious spyware tricking users into purchasing their software. Now there's a new SpywareQuake variant released, <b>C:\Windows\System32\dvdcap.dll.</b>  If you have <b>dvdcap.dll</b> on your computer, you may be infected with SpywareQuake.</p>

<p><a href="/FreeSpywareScanner.exe">Remove SpywareQuake</a> and it's variant dvdcap.dll automatically -- <a href="/FreeSpywareScanner.exe">click here</a> (Fast &amp; Easy). </p>

<p>Manually remove <b>dvdcap.dll</b> from the following registry keys:<br />
<font size="1"><b>Note:</b> Manual removal can be dangerous. Avoid damaging your machine, <a href="/FreeSpywareScanner.exe">scan your computer</a> for SpywareQuake. </font></p>

<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
SharedTaskScheduler]<br />
“{1C3B31AE-FD16-D2CE-43FF-DC4CD5C1BC5E}”=”CD-DVD Device”</p>

<p>[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\<br />
{1C3B31AE-FD16-D2CE-43FF-DC4CD5C1BC5E}\InProcServer32]<br />
@=”C:\WINDOWS\system32\<font color="#FF0000">dvdcap.dlll</font>"</p>

<p>SpywareQuake manual removal instructions available, <a href="/Remove-Spyware/2006/05/spywarequake_removal_how_to_re_1.php">click here.</a></p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spy_quake_variation_dvdcap.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/new_spy_quake_variation_dvdcap.php</guid>
         <category>SpywareQuake</category>
         <pubDate>Fri, 12 May 2006 09:17:33 -0500</pubDate>
      </item>
            <item>
         <title>WinFixer Removal - How to Remove WinFixer</title>
         <description><![CDATA[<p>WinFixer is an anti-spyware program that secretly installs a trojan onto your computer and displays false security <br />
notifications in attempt to get you to buy their software.</p>

<p>You may be infected with WinFixer, if you detect <b>C:\Program Files\WinFixer\WinFixer.exe</b> on your computer. </p>

<p><u><b>Remove WinFixer</b></u><br />
Choose SpySheriff removal procedure:</p>

<p>- WinFixer Automatic Removal, <a href="/FreeSpywareScanner.exe">click here.</a> (Fast &amp; Easy.) </p>

<p>- WinFixer Manual Removal, <a href="#winfixer_manual_removal">click here.</a> (Some technical skills required.)</p>

<p><b>WinFixer Image</b></p>

<p><img alt="winfixer-image.jpg" src="/Remove-Spyware/winfixer-image.jpg" width="500" height="352" /></p>

<p><br />
<u><b><a name="winfixer_manual_removal">SpyAxe Manual Removal Instructions</a></b></u></p>

<p><b>Note:</b> This manual removal process can be difficult. To avoid unnecessary risk of destroying your computer, use this <a href="/FreeSpywareScanner.exe"> automatic check</a> to detect and remove WinFixer.  </p>

<p><b>Detect and remove these WinFixer processes:</b><br />
winfixerscannerinstall.exe <br />
winfixer2005setup.exe <br />
winfixer20.exe </p>

<p><b>Delete these WinFixer DLL files:</b><br />
df_fixer.dll <br />
df_proxy.dll <br />
ffcom.dll <br />
ffwraper.dll </p>

<p><b>Remove these WinFixer registry values:</b><br />
HKEY_CURRENT_USER\software\winsoftware\winfixer 2005\settings installdate <br />
HKEY_CURRENT_USER\software\winsoftware\winfixer 2005\settings last_scan_high <br />
HKEY_CURRENT_USER\software\winsoftware\winfixer 2005\settings last_scan_low <br />
HKEY_CURRENT_USER\software\winsoftware\winfixer 2005\settings last_timeout_high </p>

<p><b>Detect and remove these WinFixer files:</b><br />
unins000.dat <br />
up.datdatabase.sav <br />
program.sav <br />
df_kmd.sys </p>]]></description>
         <link>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winfixer_removal_how_to_remove.php</link>
         <guid>http://www.2-freespywareremoval.com/Remove-Spyware/2006/05/winfixer_removal_how_to_remove.php</guid>
         <category>WinFixer</category>
         <pubDate>Wed, 10 May 2006 10:13:41 -0500</pubDate>
      </item>
      
   </channel>
</rss>
