XP Internet Security 2012 is a rogue security program that is promoted through the use of Trojans. Once installed, trojans will impersonate an Automatic Windows Updates window and download the bogus program onto your computer. When this fake program is running, it will simulate a system scan and display a list of false system security threats. Moreover, XP Internet Security 2012 will flood your computer with fake security warnings and impersonate Windows Security Center to make this scam look more realistic.
This virus will also hijack your web browser and block antivirus and anti-spyware programs. Finally the rogue program will ask you to pay for a full version of the program to remove the non-existing infections. Don't purchase it and remove XP Internet Security 2012 virus from your computer as soon as possible.
The bad news is that XP Internet Security 2012 (another name of virus) protects itself quite effectively. It blocks legitimate security software and hijack web browsers. In some cases it blocks all programs, not only anti-virus or anti-spyware software. What is more, it will detect many of well known and reputable websites as harmful and display fake security alert stating that you may infect your PC if you open a particular website. And of course, it disables certain Windows functions such as Task Manager, Regedit and etc. It's possible to remove it manually, but you have to re-enable those Windows functions at first. You may also download an automatic removal tool, but again have to fix some registry entries and terminate the main process of XP Internet Security 2012 which is kdn.exe to be able to run the removal tool.
To disable this scamware, also try using its registration codes. Enter one of these: 1147-175591-6550, 2233-298080-3424 or 9443-077673-5028. Additionally, download and update a reputable anti-spyware program and run a full system scan.
XP Internet Security 2012 manual removal:
Kill processes:
kdn.exe
Delete registry values:HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'
Delete files:%AllUsersProfile%\Application Data\u3f7pnvfncsjk2e86abfbj5h %LocalAppData%\kdn.exe %LocalAppData%\u3f7pnvfncsjk2e86abfbj5h %Temp%\u3f7pnvfncsjk2e86abfbj5h %UserProfile%\Templates\u3f7pnvfncsjk2e86abfbj5h
kill process: tlf.exe
delete file: [user]local settingsapplication datatlf.exe
delete registry values included up there and these 4:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterAntivirusDisableNotify
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterFirewallDisableNotify
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterUpdatesDisableNotify
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionExplorerAdvancedFolderHiddenShowallCheckedValue = (Hijack.system.hidden)
and then run a scan.
I too had this issue to deal with last week – very frustrating having my system (Windows XP) hijacked and ransomed at $59.95. I absolutely refused to pay it! After hitting the web and seeing that it was a serious issue, I look for a solution. Although I am tech savvy, I found the solutions to be too intense for me, in fact, I almost considered taking it to my computer guy. Well, I used some common sense (no offense IT guys) and I was able to fix my problem.
I remind you that I do have a comfort level in deleting and installing stuff so please only do this if you know what you are doing.
NUMBER 1
I did start with the Task Manager and closing all the .exe that started with 3 letters as the forums stated. I had 3 or 4. That did not work and I did not know which was the culprit.
NUMBER 2
I got tired of closing the windows when they popped up so I minimized them. At that point I realized that the flashing window displayed OAP, which was one of the processes I had disabled. BECAUSE I STILL HAD THE TASK MANAGER WINDOW OPEN I NOTICED THAT THIS OAP PROCESS KEPT POPPING BACK UP SO I KNEW THIS WAS THE CULPRIT.
NUMBER 3
I did a search on my C drive for the oap.exe file and located it. There was another OAP file that I also deleted (there were only 2).
However, I could not delete the files because they were being used (SAID ACCESS DENIED, FILE IN USE or something like that). It then occurred to me that I had a timeframe of about 5-7 seconds to close the OAP process and then jump back to the file location and delete them. And that my friend did the job.
NUMBER 4
I did have a problem opening .EXE files so I repaired my registry with the WINXP_EXE_FIX.REG but I have no idea where I got it so you will have to do a search on how to fix this should it be deem necessary.
My system has been working fine since. I truly hope this works for you.
Pamela
michy240@hotmail.com
There is also another registry value of the spyware located in:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun1106131116
This link helped me fix the problem:
http://filext.com/faq/broken_exe_association.php
The below registry value was the only one altered on my system.
[HKEY_CLASSES_ROOT.exe]
default="exefile"
"Content Type"="application/x-msdownload"
After correcting it and following all of the instructions on this page I was able to download and install Malwarebytes and my system is working fine again.
Post Comment: