Subject: The subject is one of the following: Re: Important Re: Your document Re: Your details Re: Approved Message: The message is one of the following: Your file is attached. Please read the document. Your document is attached. Please read the attached file. Please see the attached file for details. Attachment: The attachment is one of the following: your_file_%s.pif, details_%s.pif, document_%s.pif, %s.pif where %s is the portion of the "To" address before the "@". Manual removal: Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the value: "HtProtect"="%Windir%\AVprotect.exe" Automatic Removal: Use RegRun Startup Optimizer to remove it from startup. ">

avprotect.exe - Dangerous

avprotect.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

avprotect.exe
W32.Netsky.L@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning hard drives and mapped drives.

Copies itself as %Windir%\AVprotect.exe.

Adds the value:
"HtProtect"="%Windir%\AVprotect.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.

Retrieves email addresses from the files that have these extensions:
.adb .asp .cgi .dbx .dhtm .doc .eml .htm .html .jsp .msg .oft .php .pl .rtf
.sht .shtm .tbb .txt .uin .vbs .wab .wsh .xml

The email has the following characteristics:
From:

Subject: The subject is one of the following:
Re: Important
Re: Your document
Re: Your details
Re: Approved

Message: The message is one of the following:

Your file is attached.
Please read the document.
Your document is attached.
Please read the attached file.
Please see the attached file for details.

Attachment: The attachment is one of the following:
your_file_%s.pif, details_%s.pif, document_%s.pif, %s.pif
where %s is the portion of the "To" address before the "@".

Manual removal:
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value:
"HtProtect"="%Windir%\AVprotect.exe"

Automatic Removal:
Use RegRun Startup Optimizer to remove it from startup.

Remove avprotect.exe now!