XP Defender 2013 is a form of a rogue antivirus program, which includes Win7 Defender 2013 and Vista Defender 2013. It imitates a real security program – it pretends to scan your computer for security infections and after the imaginary scan this bogus software generates a fake list of supposedly detected security threats. All of the processes which imitates a legitimate security program are displayed with a purpose of tricking unsuspecting PC users into purchasing a licence key for XP Defender 2013. This malicious software originates from a family of fake antivirus programs called Braviax, previously released rogue programs from this family were named Win7 Security 2012, Win7 Antivirus 2012 and many other. This family or rogues were inactive for about 6 months, but apparently Cyber criminals decided to renew the development and distribution or fake antivirus programs from this family.
Proceed to removal instructions
Fake security warning messages generated by XP Defender 2013:
“Attention: Danger!
Alert! System scan for spyware, adware, Trojans and viruses is complete. XP Defender 2013 detected 31 critical system objects. These security breaches may be exploited and lead to the following:
Your system becomes a target for spam and bulky, intruding ads
Browser crashes frequently and web access speed decreases
Your personal files, photos, document and passwords get stolen
Your computer is used for criminal activity behind your back
Bank details and credit card information gets disclosed”
“Click Register to register your copy of XP Defender 2013 and perform threat removal on your system. The list of infections
and vulnerabilities detected will become available after registration”
“Computer security is at risk! Your PC is still under malware attack. Dangerous programs were found to be running in the background. System
crash and identity theft are likely. Remove malware now and get real time intrusion protection?”
“System hijack!
System security threat was detected. Viruses and/or spyware may be damaging your system now. Prevent infection and data loss or stealing by running a free security scan”
“Security breach!
Beware! Spyware infection was found. Your system security is at risk. Private information may get stolen, and your PC activity may get monitored. Click for an anti-spyware scan”
“Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card
details and passwords. Click here to perform a security repair”
“Virus infection!
System security was found to be compromised. Your computer is now infected. Attention, irreversible system changes may occur. Private data may get stolen. Click here now for an instant anti-virus scan”
“XP Defender 2013 ALERTSystem integrity threat!
Warning! Sensitive data may be sent over your Internet connection right now!
Details Attack from 252.211.92.28 port: 20928
Attacked port: 35268
Threat: Trojan-Proxy.Win32.Agent.x
Do you want to block this attack?”
Don’t trust this program.This is a fake antivirus software. Remove it. Use this removal guide to completely remove XP Defender 2013 from your computer.
XP Defender 2013 rogue removal:
Step 1. Download removal software
To download Trojan Killer from the infected machine, press [Win]+R (or click Start then click Run). In the dialog window that appears type ‘http://trojan-removal-guide.com/trojankiller.php’ and press ENTER.
XP Defender 2013 will generate fake warning after pressing ENTER. Please ignore it and click “No, stay unprotected (Not recommended)”. File download dialog will appear saying you are downloading file trojan_killer-setup.exe. Click Save, wait for download to finish.
If download does not start, you should download the installation file using this link on other computer and use a USB flash drive to move it to the infected PC.
Step 2. Install Trojan Killer
To run the installation, right-click the file you’ve just downloaded, and choose Run as. In the dialog window that appeared uncheck the checkbox as displayed below:
Important! Don’t uncheck the ‘Start Trojan Killer’ checkbox at the end of installation!
Step 3. Remove the XP Defender 2013 files and fix the system
In the window that appeared click ‘Start scan’ and let the Trojan Killer program do its job. Unlike other anti-malware programs, it will not only remove the virus files. It will fix all the aftermathes of Win7 Defethe Windows Registry entries, fix Proxy Server settings and restore the ‘hosts’.
Technical Details
Registry entries, created or modified by XP Defender 2013:
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\ [rnd_0]
HKEY_CURRENT_USER\Software\Classes\.exe\Content Type application/x-msdownload
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon\ %1
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\IsolatedCommand “%1″ %*
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\ “%1″ %*
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\IsolatedCommand “%1″ %*
HKEY_CURRENT_USER\Software\Classes\[rnd_0]
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\ Application
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\Content Type application/x-msdownload
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon\ %1
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\IsolatedCommand “%1″ %*
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\ “%1″ %*
HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\IsolatedCommand “%1″ %*
Files, created by XP Defender 2013:
%LocalAppData%\[rnd_2]
%Temp%\[rnd_2]
%UserProfile%\Templates\[rnd_2]
%CommonApplData%\[rnd_2]








