Tuesday, January 10, 2012

Remove Windows 7 Security 2012Remove Windows 7 Security 2012

Remove Windows 7 Security 2012
Windows 7 Security 2012 is a fake antivirus program that perform like a real antivirus such as Kaspersky Anti-Virus, AVG Free Antivirus, Avira AntiVir etc. Windows 7 Security 2012 infects the computer when the user accidentally downloads a trojan from a website which provide online videos. Windows 7 Security 2012 will start automatically when Windows boot. Then, Windows 7 Security 2012 will scan the computer and produce fake scan results and display many fake alerts to urge the user to purchase the full version of Windows 7 Security 2012 in order to remove the detected malwares.

Windows 7 Security 2012 provides fake features such as System Scan, Protection, Privacy and Update. None of them can really protect computer from malware, virus or trojans.Windows 7 Security 2012 should be removed immediately!

Windows 7 Security 2012 Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe

Delete Registry

HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah
HKEY_CLASSES_ROOT\ah
HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"
HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*
HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*


Remove Folders and Files

%AppData%\Microsoft\Windows\Templates\[random]
%LocalAppData%\[random]
%LocalAppData%\.exe[random]
%AllUsersProfile%\[random]
%Temp%\[random]
%AppData%\Microsoft\Windows\Templates\[random]
%LocalAppData%\[random]
%LocalAppData%\.exe[random]
%AllUsersProfile%\[random]
%Temp%\[random]

No comments:

Post a Comment