Wednesday, June 8, 2011

Win 7 Internet Security 2012 removal tips and tricks (manual guide)

Self-promotion may be more destructive than activities of a dozen of viruses. Get rid of Win 7 Internet Security 2012 at the earliest opportunity, for the program, being mainly known for faking security tools for Windows, promotes itself  at the expense of user’s convenience and badly corrupts computer system hosting it..
The idea of the parasite is to draw user’s attention to security problems in the following way:
First, the program arranges system or software error. The error is immediately commented by its popup that names imaginary reason for it and prompts user to buy the fake antivirus in order to fix the  error.
Such scheme makes the adware popups more convincing than usual alert of counterfeited security tools, even more convincing than alerts of true security solution, for on rare occasion an alert on threat detected is associated so obviously with the damage caused by threat.
Now you know that the program is but extremely malicious fake antispyware. Repair the damage it has already caused and ensure Win 7 Internet Security 2012 removal following the free scan link.

Interface snapshot:


Win 7 Internet Security 2012 remover:



Win 7 Internet Security 2012 uninstalling instructions:
Delete infected files:
%AllUsersProfile%\Application Data\u3f7pnvfncsjk2e86abfbj5h
%LocalAppData%\kdn.exe
%LocalAppData%\u3f7pnvfncsjk2e86abfbj5h
%Temp%\u3f7pnvfncsjk2e86abfbj5h
%UserProfile%\Templates\u3f7pnvfncsjk2e86abfbj5h
Delete infected registry entries:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates” = ‘1′
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ‘1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ‘1′

5 comments:

Stan said...

i cant open registry, it wont let me me

Anonymous said...

open regedit as administrator

PV said...

Run regedit as administrator

Anonymous said...

i used stopzilla, in safe mode with network enabled, found 3 major problems, my mcafee didn't. or try a free version of avg downloaded in safe mode and see if that helps. it took me 4 hrs to rid myself of this one. hope this helps

Anonymous said...

IM UNAble t delete the last 2...:(