Friday, December 9, 2011

Remove XP Home Security 2012 fake that resists to uninstalling

XP Home Security 2012 pretends to know how to scan computer memory and delete viruses. Pretend you believe it and remove XPHome Security 2012.
Please do not try uninstalling the program, for its developers took care of its protection. The malware is made in such a way as to be not available for uninstalling. Moreover, it can register an attempt of user to get rid of it through uninstalling and, if conditions so provide, notify remote server of the event. That may cause rootkits delivery. The rootkits may seriously aggravate extermination of the parasite, however it is not a formidable obstacle for removal solution of due quality.
Click here to get rid of XP Home Security 2012 fake antispyware relying on completing free scan that indeed detects and removes viruses of any payload and complexity. 

XP Home Security 2012 screenshot:




Manual  removal guide for XP Home Security 2012:
Delete infected files:
C:\Documents and Settings\All Users\[SET OF RANDOM CHARACTERS]
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS]
C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe
C:\Documents and Settings\[UserName]\Templates\[SET OF RANDOM CHARACTERS]
C:\Documents And Settings\[UserName]\Local Settings\Temp\[SET OF RANDOM CHARACTERS]
Delete infected registry entries:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exee" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\com​mand "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode​\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\co​mmand "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


Rename the remover to "explorer.exe" or try to install from Safe Mode is virus blocks download\installation

No comments: