Jun 08

Malware Analysis:

XP Antispyware 2012 is a perilous utility whose activity on your PC is hard to label safe or normal whatsoever. It attacks your computer in an awfully outrageous manner, showing no signs of this intrusion and doing its very best to not get spotted. If it works (which it unfortunately very often does), then the reign of XP Antispyware 2012 virus on your machine will be doomed to start. What a mess will be observed shortly after this silent infiltration! This self-proclaimed antivirus will try exhibiting its allegedly unique and effective skills for fighting malware. But before actually heroically combating viruses, XP Antispyware 2012 first needs to find them on your computer. Is your PC virus-free? Well, that’s not a problem for the application we are discussing here. It can make them up, and it actually does so by issuing absurdly misinforming scanners and weird pop-ups now and again. Concerning the scanners, they have all the necessary external attributes like the progress bar, configuration button, firewall, proactive defense and even support option. That sure resembles a regular scan from an ordinary AV tool. But wait and see what happens next. XP Antispyware 2012 lists tons of infections when through even though your computer is most likely to be as clean as the water in a mountain river. At that point, the Registration option comes out of shade as XP Antispyware 2012 offers you get rid of the threats that had been found (allegedly). So you will be forced into paying for the full commercial version of this sham software, which we strongly advise you not do. We know no correct path except removing XP Antispyware 2012 rogue.

Determine if your PC is infected with XP Antispyware 2012:

XP Antispyware 2012 Screenshot:

XP Antispyware 2012 Screenshot

How to remove XP Antispyware 2012 manually:

To perform manual removal of XP Antispyware 2012, you should do the following:

Delete XP Antispyware 2012 corrupt files:

  • %Documents and Settings\All Users\[random characters]
  • %Documents and Settings\[UserName]\Application Data\[random characters]
  • %Documents and Settings\[UserName]\Local Settings\Application Data\[three random characters].exe
  • %Documents and Settings\[UserName]\Templates\[random characters]
  • %Documents And Settings\[UserName]\Local Settings\Temp\[random characters]

Remove the following associated registry entries:

  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates” = ’1′
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
  • HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1″ %*’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ’1′
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ’1′

Please note that manual removal of XP Antispyware 2012 is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download XP Antispyware 2012 Removal Tool

Leave a Reply