XP Defender Plus 2013 virus. How to remove it

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)

If you are browsing through this newsletter telling of XP Defender Plus 2013 scam this probably implies that somehow you are interested to find out the answer to the question – how to delete this scareware from your workstation. We really regret that your computer has been poisoned with this malware. We regret that you have become one of the victims of cyber crooks with the craziest of intentions. It was made specifically to reap earnings from unwary users, making them to get tempted to obtain it due to the fact that this hoax represents plenty of frightening information about the condition of their machines and indicates that its registered version will be able to repair them. At the same time, all such information presented by this scam is fictitious and should be entirely disregarded.

XP Defender Plus 2013 doesn’t care whether you want to see it or not on your machine. It also modifies your system settings in order to be self-started automatically together with every system startup. Hence, you will see this hoax each time you turn the PC on.

This is when the true thoughts of XP Defender Plus 2013 are made known, cause it would initiate fictitious system scan with same fake subsequent horrifying reports about lots of issues and errors with your system. XP Defender Plus 2013 would say that it is the ideal answer to have all these bugs and errors dealt with, however, you would be first instructed to obtain its registered version. What a fraud approach indeed! This is totally idle and pointless tool which cannot fix real problems or delete actual viruses and threats from your computer. It will not help even if you get its so-called full version. Thus, do not buy this scam, no matter how convincing it is in its numerous attempts to persuade you to do so.

XP Defender Plus 2013 similar removal video guide:

XP Defender Plus 2013 step-by-step removal instructions from GridinSoft Trojan Killer anti-virus Lab

Step 1.

Run GridinSoft Trojan Killer. Click Win+R and type the direct link for the program’s downloading.

If it does not work, download GridinSoft Trojan Killer from another uninfected machine and transfer it with the help of a flash drive.

Step 2.

Install GridinSoft Trojan Killer. Right click – Run as administrator.

Run as administrator


Don’t uncheck the Start Trojan Killer checkbox at the end of installation!


Manual removal guide of XP Defender Plus 2013 virus:

Delete XP Defender Plus 2013 files:

  • %LocalAppData%\[rnd_2]
  • %Temp%\[rnd_2]
  • %UserProfile%\Templates\[rnd_2]
  • %CommonApplData%\[rnd_2]

Delete XP Defender Plus 2013 registry entries:

  • HKEY_CURRENT_USER\Software\Classes\.exe
  • HKEY_CURRENT_USER\Software\Classes\.exe\ [rnd_0]
  • HKEY_CURRENT_USER\Software\Classes\.exe\Content Type application/x-msdownload
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon\ %1
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\ “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\ Application
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\Content Type application/x-msdownload
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon\ %1
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\ “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\IsolatedCommand “%1″ %*
(Visited 226 times, 1 visits today)

Related posts:

Leave a Comment