Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Remove Rogue Win 7 Antivirus 2012 By Britec

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
28,183
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 1, 2011

Remove Rogue Win 7 Antivirus 2012 By Britec.co.uk

What this infection does:

Win 7 Antispyware 2012, Vista Antivirus 2012, and XP Security 2012 are all names for the same rogue anti-spyware program. This family of rogues is promoted in two ways. The first is through the use of fake online antivirus scanners that state that your computer is infected and then prompt you to download a file that will install the infection. The other method are hacked web sites that attempt to exploit vulnerabilities in programs that you are running on your computer to install the infection without your knowledge or permission. Regardless of how it is installed, once it is running on your computer it will install itself as a variety of different program names and graphical user interfaces depending on the version of Windows that is running. Regardless of the name, though, they are all ultimately the same program with just a different skin on it. This rogue goes by different program names, which I have listed below based upon the version of Windows that it is installed on:

When installed, this rogue pretends to be a security update for Windows installed via Automatic Updates. It will then install itself as a single executable that has a random consisting of three characters, such as kdn.exe, that uses very aggressive techniques to make it so that you cannot remove it. First, it makes it so that if you launch any executable it instead launches Vista Home Security 2012, XP Internet Security 2012, Win 7 Security 2012, or any of the other names it goes under. If the original program that you wanted to launch is deemed safe by the rogue, it will then launch it as well. This allows the rogue to determine what executables it wants to allow you to run in order to protect itself. It will also modify certain keys so that when you launch FireFox or Internet Explorer from the Window Start Menu it will launch the rogue instead and display a fake firewall warning stating that the program is infected.

Fix Shell:

http://www.briteccomputers.co.uk/downloads/FixRegistryNCR.reg

Rogue killer:

http://tigzy.geekstogo.com/Tools/RogueKiller.exe

HiJackfree:

http://download3.emsisoft.com/a2HiJackFree.exe

Rkill:

http://download.bleepingcomputer.com/grinler/iExplore.exe

Malwarebytes:

https://store.malwarebytes.org/342/cookie?affiliate=1878&redirectto=http%...
----------------------------------------------------
need help removing malware?
http://www.briteccomputers.co.uk/forum
--------------------------------------------------
http://www.britec.org.uk
http://www.pcrepairhertfordshire.co.uk

Link to this comment:

Share to:
see all

All Comments (270)

Sign In or Sign Up now to post a comment!
  • this guy is legit thanks so much for the shell fix i need that

  • @SatyamSadaye02 Wow really this guy is probably an expert on computers and you just a little kid that think's restoring is the answer.

  • DONOT DO THIS LONG PROCESS JUST DO SYSTEM RSTORE!!!!

  • You guys could Be safe, if you didnt just Retry the download, when u get an note from ur antivirus its an Malware or Trojan. I kinda Feel that u guys are dumn (some) that dont follow ur antivirus and having it for a waste time.

  • it won't let me download malware bytes

  • @tjbalon I got it fixed, but thanks anyways man

  • @soulrider1monounit

    before or after you followed his steps on trying to remove the file? or are you still working on downloading the files

  • Thank you from Canada!! This was driving me nutty!! Thanks alot you saved me!!

  • Links don't work... I live in the US

  • i have ripristin to system!

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more