Win 7 Antivirus 2012 is yet another rogue anti-spyware program. It's distributed through the use of Trojans just like all the other rogue programs out there. Trojans may come from fake online scanners, infected or malicious video sites. The scammers also distribute their bogus software on the biggest social networks, so be aware.
As a typical rogue program, Win 7 Antivirus 2012 reports false system security threats and displays fake security alerts to scare you into thinking that your computer is infected with malicious software. Then it will ask you to pay for a full version of the program to remove the infections. To make you scared, these scams will display such alerts:
Vista Security 2012 Alert
Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site’s pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.
Things you can do:
- Get a copy of Vista Security 2012 to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)
Sensitive areas of your system were found to be under attack. Spy software attack or virus infection possible. Prevent further damage or your private data will get stolen. Run an anti-spyware scan now. Click here to start.
Keep in mind taht the scan results are false and the reported infections don't actually exist. Don't pay for this bogus software and uninstall it form your computer upon detection. Once running, Win 7 Antivirus 2012 will also block legitimate and well known anti-virus and anti-spyware programs to protect itself from being removed. To make things worse, it will probably block task manager and registry editor as these tools are very helpful when removing Win 7 Antivirus 2012 virus. You will have to complete several additional steps to make your PC work again. Please follow the removal instructions below to remove Win 7 Antivirus 2012 infection from your computer completely.
If you are disabled from launching your anti-spyware, please enter one of these registration codes that will make your virus believe you have purchased it: 2233-298080-3424, 1147-175591-6550, 3425-814615-3990, 9443-077673-5028. After disabling your virus, download and update reputable anti-spyware and run a full system scan to remove all infected files of Win 7 Antivirus 2012.
It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
and Agreement of Use
Win 7 Antivirus 2012 manual removal:
Delete registry values:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'