YYY is a security program, which is a totally fake one, and it belongs to the family of fakeries as XXX that has been infecting secretly through Trojans. This program is distributed by fake social engineering, fake updates and malicious downloads. As it penetrates in your system, it targets your computer and changes critical values like registry keys, system files and adds its own registry entries. This helps in the running the malicious applications of YYY. Moreover, it launches this bogus every time your computer boots. Furthermore, it starts an automatic scanning process of your system and reports false infection within seconds and keeps on sending security warnings.

It displays many fake security alerts and warnings for example:

Warning! spambot detected!

Attention! A spambot sending viruses from your email has been detected on your PC

Like fake scanner result, the warnings YYY continuously sends are also false and bogus. However, sometimes, the files it shows do not even exist at all, so you can ignore them safely. If you want to remove this malicious software from your system, follow the instructions:

Remove YYY processes

  1. To remove the YYY you need windows task manager.
  2. You can open the task manager directly by pressing the keys CTRL, Shift and ESC from the keyboard.
  3. Select the ‘processes’ tab from the task manager window.
  4. Find out the YYY processes which are named as:



  1. Click on the processes and then press the key Delete to remove the processes.

Remove YYY registry key values

  1. Click on the start button and then select the option run from the menu.
  2. Type regedit click Ok.
  3. From the left section of the editor click on Edit and further on Find.
  4. Enter the YYY registry key values and then press enter.
  5. Select the found registry entry values and press the Delete key from the keyboard to remove the registry entry values.
  6. The YYY registry key values that must be deleted are:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ Main \ FeatureControl \ EATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Policies \ System “DisableRegedit” = 0

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Policies \ System “DisableRegistryTools” = 0

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Policies \ System “DisableTaskMgr” = 0

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Run “Inspector”

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Settings “ID” = 0

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Settings “net” = “2012-2-17_2″

HKEY_CURRENT_USER \ Software \ Microsoft \Windows \ CurrentVersion \ Settings “UID” = “rudbxijemb”

HKEY_LOCAL_MACHINE\SOFTWARE \ Microsoft \Windows NT \ CurrentVersion \ Image File Execution Options \_avp32.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\divx.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\mostat.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\platin.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe

HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft \Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe

Remove YYY other files

  1. Click on Start button and then select the option search.
  2. Write the YYY file name in the given space one by one.
  3. Do not forget to check the option ‘My computer’ to get the results quickly.
  4. The YYY other file names are:



How to Remove YYY?
