Antivirus XP 2008 Removal Guide

Threat Level:
9/10
Rate this Article:
Comments (0)
Article Views: 12077
Category: Fake Antispyware

There are many ways for rogues such as Antivirus XP 2008 to arrive at your computer. In this case, the rogue antispyware application is being promoted and advertised via Trojans and other types of malware. In general, such infections can spread via spam email or social engineering. When you receive an email message from an unknown sender that is absolutely random, you should not open an attachment if there is one, or try and click on the link that is embedded on the message. It is very likely that you would end up being infected with Antivirus XP 2008 eventually.

Also, there are a lot of fake security alerts on the websites that you visit on daily basis, so if you click on any of these ads it is also possible to get infected with Antivirus XP 2008. In a nutshell, you would save yourself a lot of trouble by not clicking anywhere. However, even if you apply all the safety measures, rogues like Antivirus XP 2008 can still enter your system, because they don’t need to prompt you about the oncoming infection, and you will become aware of it only when the rogue’s interface pops into your screen.

Actually, Antivirus XP 2008 looks like a legitimate program, because it copies the color scheme and logo of official Windows products. For users who are not very much computer-savvy Antivirus XP 2008 can definitely seem reliable, especially as it launches a full system scan and finds a lot of viruses, giving description, level of threat and status. It says “Alert! Your system is infected!” and then offers to Remove Viruses. Don’t miss the golden tab at the left bottom corner of the interface which “Get Maximal Realtime Protection with Antivirus XP 2008”.

It implies that you would need to pay for the activation or the registration of this program in order to acquire this ultimate real time protection. That is absolutely out of question, because if you pay, you would reveal your credit card number, expiration date and the CVV2 to a third party thus giving a key to your bank account to cyber criminals. Of course, it is understandable that you would want to remove these parasites from your computer that are slowing down your system a great deal, but the truth is that the only thing slowing your computer down is Antivirus XP 2008 itself.

Your problems will be gone if and when your remove Antivirus XP 2008. Acquire a legitimate antimalware tool that will terminate the rogue and will help you to look for other malicious threats in your system, because Antivirus XP 2008 seldom comes alone.

Download Remover for Antivirus XP 2008 *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

Antivirus XP 2008 Screenshots:

Antivirus XP 2008

Antivirus XP 2008 technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1rhcg4kj0e98e.exe
2rhcpwqj0ej27.exe, rhce80j0e11g.exe9457664 bytesMD5: 30e26e1a6a81503bd3c6008486386ca1
3pphcn3jj0epf7.exe
4vav.exe325632 bytesMD5: 4f94513287f9f829d4ef2b0bd177bd5e
5rhcgedj0ep8l.exe
6%AllUsersProfile%\Start Menu\Programs\Antivirus XP 2008
7AntivirusXP.exe1512960 bytesMD5: d30b70479b5949ede657231ecd974aa4
8antivirus-2008pro.exe1231064 bytesMD5: 4c372f908aa1abc8b7184c49f1ac089c
9lphcrw3j0e5e5.exe199168 bytesMD5: 4740615d379ec65e77d6414c1e9de9ca
10av2008xp.exe,Install_1_1_[1].exe1233920 bytesMD5: 18db68b9045c0fe8096e0e46c95cb365
11pphc38wj0e7er.exe
121scan31[1].exe
13lphcef9j0e15r.exe110080 bytesMD5: 158da82d501be7e394b0327bcff04981
14vvunbwrhxa.exe132096 bytesMD5: f6eca74cd80fe171003f71a5aede2ff4
15Antivirusgolden 3.8.exe2080768 bytesMD5: 2ff9e315a9b6d340b2daa6e4ee8d03d6
16pphc31wj0e9ea.exe
17pphclpmj0e73r.exe
18rhctp3j0en6c.exe
19Antivirusgolden 4.0.exe1953792 bytesMD5: cf5a5c661b9cb6fce5cc92ac6f906c16
20rhcn7cj0ea59.exe.local
21lwpwer.exe, empa.exe1189857 bytesMD5: c91ef4d73d64d00663c04adf19b5782b
22lphcjosj0e9e5.exe114176 bytesMD5: 1f07bc3c130b2ccd952c01588e3fdc6f
23pphcvmfj0e5a1.exe
24.tt7.tmp.exe1603919 bytesMD5: 07a690fe30506a1a1a4e4f997d044dd4
25Antivirusgold 4.1.exe1994752 bytesMD5: 43285e38f15090960a3ff09ff2a5803a
26pphcr66j0e11c.exe
27xpa_2008.exe1050624 bytesMD5: 8130d8a90b89b07f52f321c1b8f89379
28lphcc3qj0eacl.exe, lphce9fj0e7jr.exe110080 bytesMD5: d6c2a10553c213e9ede4f62137e45338
29yayxuRJc.dll321792 bytesMD5: 08a133614055caf4cd5f2afd77e36e5c
30AntvrsInstall.exe52224 bytesMD5: 4a574021ce73bdade5281b52ef667f72
31av[1].exe462848 bytesMD5: d4ddb37ef8f171406e117d3dc7d99f6f
32lphccn4j0eadc.exe110080 bytesMD5: 00fe0f3086a6e4297f901f60516de0a6
33lphc110j0e78a.exe134144 bytesMD5: 765f909fc1b15d20796cfa467bcafc57
34ave.exe200192 bytesMD5: f3daefe27408c203ef4a4c19f06039e3
35scan16085[1].exe195072 bytesMD5: 0c575193d1a1344f01b844b7911ff716
36wscntfy.exe30408704 bytesMD5: f95cbc60e79ae4f0e9efdc1a4d3819ae
37lphcj7cj0ea59.exe110080 bytesMD5: d85e0a81c0c3665f36c17ed001f578c1
38rhc13bj0e73j.exe831488 bytesMD5: f1692980a3ab58a22b33442cfd8f9c23
39%AppData%\rhcn7cj0ea59
40bpphcj7cj0ea59.exe106496 bytesMD5: 83eae4fc14acd18de28b313c821ca235
41lphcgl5j0en59.exe35328 bytesMD5: 2913d35231da4c43a380e10a6c0e6643
42How to Register Antivirus XP 2008.lnk
43rhcn7cj0ea59.exe9457664 bytesMD5: e41af37d5cd6508107efb81784f77e59
44lphca80j0e11g.exe130048 bytesMD5: c0776ab5d08df451897670752548f95b
45antiviirus.exe10240 bytesMD5: f811c4377332c81fde4e4dfa1c6d5ea0
46pphc1q9j0e5vc.exe
473.exe827392 bytesMD5: 1fc7d7591e0edcad45565ccda51a4528
48scan[1].exe60928 bytesMD5: a45e0c5d415f7a9ce0eed56d177e40ed
49pphcruaj0e355.exe
501450345358.exe
51rhcg2sj0ep0c.exe831488 bytesMD5: 0f79fbdbcf2a416d1831570f461f8240
52Antvrs.exe878592 bytesMD5: 650a6cb1433b764e27ea59d2eca999a3
53Antivirus-2008.exe1075712 bytesMD5: aa8ea9ef0820268d9246ff3d3d5422ac
54pphcahoj0ercl.exe106496 bytesMD5: 69534bea316938567b5c53e697d21222
55lphcj7cj0ea59.exe,04scan[1].exe,584289103.exe152576 bytesMD5: 17aa05f3c70e113770e62d4875c13c0d
56ieupdates.exe
5726scan[1].exe
58vma.exe182784 bytesMD5: a409477352916aac173b02b747151b7f
59lphc748j0elfp.exe110080 bytesMD5: 715b63c8e14e093ab269f665a0e88bdb
60av.exe178688 bytesMD5: 5f966fac2df8730c9db4b0f4f6ee4238
61lphc1tgj0e5e9.exe110080 bytesMD5: ce564d30ec9bbbc8278661b54f9a16db
62xpa2008.exe1056256 bytesMD5: 6a616e48b6bdbf0796a5a598fe5aef9b
63AntivirusXP2008.exe1671168 bytesMD5: 3c23036f83013ced69398c50c1d8cc46
64Antivirus XP 2008.lnk
65setup_1_1_[1].exe69120 bytesMD5: 698dee2006883c23b3b7abcc29facc1f
66.tt5E.tmp.exe1606431 bytesMD5: 0ac13469fe7054790800fd8e24d8c5df
67.tt89.tmp1589014 bytesMD5: 626018abdf88b5134601723c9b6bde47
68av2008xp.exe1227264 bytesMD5: 04a76850419d15ed8f713a38d8e55865
69pphcn4nj0e58t.exe
70lphc395j0ee2a.exe110080 bytesMD5: 7ce64667732234eca965e01c4d0106a2
71Register Antivirus XP 2008.lnk
72imod3.dll
73wav.exe325632 bytesMD5: 4fbc16d94ea226f7278e294e0044b2b0
74pphc1kdj0elbj.exe
75642292000.exe
76Antivirus-Golden.exe2273280 bytesMD5: 03b478b848cea9282dc964dfd10ee8e0
77MSASCui.exe183808 bytesMD5: 912cfea4c8420146d77900a115c07097
78SetupAntivirusXP[1].exe804864 bytesMD5: bf5de889078aafe7af90d5d5e176db6a
79lphcrkkj0erbr.exe110080 bytesMD5: 0d0d2b357df5205bbce414e514be6b7e
80pphcjuej0en4o.exe
81lphcg1gj0er7r.exe110080 bytesMD5: f5624d97a72e252d1fa252edc1fab213
82rhca9fj0e7jr.exe9457664 bytesMD5: 83259ea84925f23ce43f526c0fc4d24b
83lphcc65j0e909.exe203776 bytesMD5: cd55078e05ec97707836e982a88336e9
84AntvrsInstall[1].exe60416 bytesMD5: fcfb95b95b2812bd93aff08e0e608667
85pphcj7cj0ea59.exe94208 bytesMD5: 43b4f1d85a9ae77a818b4ffec7984247
86AntivirusGolden.exe2273280 bytesMD5: 471977806c4ceba71cbe040885b200a8
87lphcjc8j0ec35.exe199168 bytesMD5: 609e59d17a35e514caea543868134d7a
88%ProgramFiles%\rhcn7cj0ea59
89rhcn7cj0ea59Skin.dll8245248 bytesMD5: 317bbd8489a60112cf4958f40cf040d1
90Setup_trsupersolution-freeantivirus_com[1].exe199168 bytes
91lphcj7cj0ea59.exe,26scan[1].exe,642292000.exe203776 bytesMD5: 619fab63e1a12f2cf948e812131dce04

Files in the following directories were modified:

  • %AllUsersProfile%\Start Menu\Programs
  • %AppData%
  • %ProgramFiles%

Memory Processes Created:

# Process Name Process Filename Main module size
1rhcg4kj0e98e.exerhcg4kj0e98e.exe
2rhcpwqj0ej27.exe, rhce80j0e11g.exerhcpwqj0ej27.exe, rhce80j0e11g.exe9457664 bytes
3pphcn3jj0epf7.exepphcn3jj0epf7.exe
4vav.exevav.exe325632 bytes
5rhcgedj0ep8l.exerhcgedj0ep8l.exe
6AntivirusXP.exeAntivirusXP.exe1512960 bytes
7antivirus-2008pro.exeantivirus-2008pro.exe1231064 bytes
8lphcrw3j0e5e5.exelphcrw3j0e5e5.exe199168 bytes
9av2008xp.exe,Install_1_1_[1].exeav2008xp.exe,Install_1_1_[1].exe1233920 bytes
10pphc38wj0e7er.exepphc38wj0e7er.exe
111scan31[1].exe1scan31[1].exe
12lphcef9j0e15r.exelphcef9j0e15r.exe110080 bytes
13vvunbwrhxa.exevvunbwrhxa.exe132096 bytes
14Antivirusgolden 3.8.exeAntivirusgolden 3.8.exe2080768 bytes
15pphc31wj0e9ea.exepphc31wj0e9ea.exe
16pphclpmj0e73r.exepphclpmj0e73r.exe
17rhctp3j0en6c.exerhctp3j0en6c.exe
18Antivirusgolden 4.0.exeAntivirusgolden 4.0.exe1953792 bytes
19rhcn7cj0ea59.exe.localrhcn7cj0ea59.exe.local
20lwpwer.exe, empa.exelwpwer.exe, empa.exe1189857 bytes
21lphcjosj0e9e5.exelphcjosj0e9e5.exe114176 bytes
22pphcvmfj0e5a1.exepphcvmfj0e5a1.exe
23.tt7.tmp.exe.tt7.tmp.exe1603919 bytes
24Antivirusgold 4.1.exeAntivirusgold 4.1.exe1994752 bytes
25pphcr66j0e11c.exepphcr66j0e11c.exe
26xpa_2008.exexpa_2008.exe1050624 bytes
27lphcc3qj0eacl.exe, lphce9fj0e7jr.exelphcc3qj0eacl.exe, lphce9fj0e7jr.exe110080 bytes
28AntvrsInstall.exeAntvrsInstall.exe52224 bytes
29av[1].exeav[1].exe462848 bytes
30lphccn4j0eadc.exelphccn4j0eadc.exe110080 bytes
31lphc110j0e78a.exelphc110j0e78a.exe134144 bytes
32ave.exeave.exe200192 bytes
33scan16085[1].exescan16085[1].exe195072 bytes
34wscntfy.exewscntfy.exe30408704 bytes
35lphcj7cj0ea59.exelphcj7cj0ea59.exe110080 bytes
36rhc13bj0e73j.exerhc13bj0e73j.exe831488 bytes
37bpphcj7cj0ea59.exebpphcj7cj0ea59.exe106496 bytes
38lphcgl5j0en59.exelphcgl5j0en59.exe35328 bytes
39rhcn7cj0ea59.exerhcn7cj0ea59.exe9457664 bytes
40lphca80j0e11g.exelphca80j0e11g.exe130048 bytes
41antiviirus.exeantiviirus.exe10240 bytes
42pphc1q9j0e5vc.exepphc1q9j0e5vc.exe
433.exe3.exe827392 bytes
44scan[1].exescan[1].exe60928 bytes
45pphcruaj0e355.exepphcruaj0e355.exe
461450345358.exe1450345358.exe
47rhcg2sj0ep0c.exerhcg2sj0ep0c.exe831488 bytes
48Antvrs.exeAntvrs.exe878592 bytes
49Antivirus-2008.exeAntivirus-2008.exe1075712 bytes
50pphcahoj0ercl.exepphcahoj0ercl.exe106496 bytes
51lphcj7cj0ea59.exe,04scan[1].exe,584289103.exelphcj7cj0ea59.exe,04scan[1].exe,584289103.exe152576 bytes
52ieupdates.exeieupdates.exe
5326scan[1].exe26scan[1].exe
54vma.exevma.exe182784 bytes
55lphc748j0elfp.exelphc748j0elfp.exe110080 bytes
56av.exeav.exe178688 bytes
57lphc1tgj0e5e9.exelphc1tgj0e5e9.exe110080 bytes
58xpa2008.exexpa2008.exe1056256 bytes
59AntivirusXP2008.exeAntivirusXP2008.exe1671168 bytes
60setup_1_1_[1].exesetup_1_1_[1].exe69120 bytes
61.tt5E.tmp.exe.tt5E.tmp.exe1606431 bytes
62av2008xp.exeav2008xp.exe1227264 bytes
63pphcn4nj0e58t.exepphcn4nj0e58t.exe
64lphc395j0ee2a.exelphc395j0ee2a.exe110080 bytes
65wav.exewav.exe325632 bytes
66pphc1kdj0elbj.exepphc1kdj0elbj.exe
67642292000.exe642292000.exe
68Antivirus-Golden.exeAntivirus-Golden.exe2273280 bytes
69MSASCui.exeMSASCui.exe183808 bytes
70SetupAntivirusXP[1].exeSetupAntivirusXP[1].exe804864 bytes
71lphcrkkj0erbr.exelphcrkkj0erbr.exe110080 bytes
72pphcjuej0en4o.exepphcjuej0en4o.exe
73lphcg1gj0er7r.exelphcg1gj0er7r.exe110080 bytes
74rhca9fj0e7jr.exerhca9fj0e7jr.exe9457664 bytes
75lphcc65j0e909.exelphcc65j0e909.exe203776 bytes
76AntvrsInstall[1].exeAntvrsInstall[1].exe60416 bytes
77pphcj7cj0ea59.exepphcj7cj0ea59.exe94208 bytes
78AntivirusGolden.exeAntivirusGolden.exe2273280 bytes
79lphcjc8j0ec35.exelphcjc8j0ec35.exe199168 bytes
80Setup_trsupersolution-freeantivirus_com[1].exeSetup_trsupersolution-freeantivirus_com[1].exe199168 bytes
81lphcj7cj0ea59.exe,26scan[1].exe,642292000.exelphcj7cj0ea59.exe,26scan[1].exe,642292000.exe203776 bytes

Registry Modifications:

The following Registry Keys were created:

  • AntivirusGolden 4.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lphcjc8j0ec35
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SMrhcn7cj0ea59
  • MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusXP.exe
  • RUNNING PROGRAM\pphclpmj0e73r.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SMrhcgedj0ep8l
  • Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntivirusXP
  • Microsoft\Windows\CurrentVersion\Run\lphcj7cj0ea59
  • Microsoft\Windows\CurrentVersion\Uninstall\rhcn7cj0ea59
  • RUNNING PROGRAM\pphcn3jj0epf7.exe
  • SMrhcn7cj0ea59
  • lphcj7cj0ea59
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9C0D6625-1D9B-48FB-BFE6-0E796464E576}
  • Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus XP 2008
  • Antivirus-Golden
  • RUNNING PROGRAM\pphcvmfj0e5a1.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ inrhc11wj0e13t
  • RUNNING PROGRAM\pphcjuej0en4o.exe
  • AntivirusXP
  • SOFTWARE\Microsoft\Windows\CurrentVersion rhcn7cj0ea59
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SM3
  • AntivirusGolden 3.8
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lphcc65j0e909
  • RUNNING PROGRAM\pphc31wj0e9ea.exe
  • RUNNING PROGRAM\pphc38wj0e7er.exe
  • RUNNING PROGRAM\pphc1kdj0elbj.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lphcjosj0e9e5
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lphc1tgj0e5e9
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SMrhcg2sj0ep0c
  • RUNNING PROGRAM\pphc1q9j0e5vc.exe
  • Microsoft\Windows\CurrentVersion\Run\SMrhcn7cj0ea59
  • RUNNING PROGRAM\.tt89.tmp
  • SOFTWARE\Microsoft\Windows\CurrentVersion\rhcn7cj0ea59
  • Software\Microsoft\Windows\CurrentVersion\RunOnce "3P_UDEC"
  • AntivirusXP2008
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\AntivirXP08
  • RUNNING PROGRAM\pphcr66j0e11c.exe
  • RUNNING PROGRAM\pphcruaj0e355.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ AntivirusXP2008
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SMrhctp3j0en6c
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\s9201
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ inrhcnvjj0epd5
  • RUNNING PROGRAM\pphcn4nj0e58t.exe
  • SOFTWARE\Microsoft\Windows\CurrentVersion "rhcn7cj0ea59"
  • AntivirusGolden 4.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SMrhcg4kj0e98e
  • rhcn7cj0ea59

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *