Severity scale:  

Win 7 Home Security 2012. How to remove? (Uninstall guide)

removal by Jake Doevan - -   Also known as Win7 Home Security 2012 | Type: Rogue Antispyware

Win 7 Home Security 2012 is a fake anti-spyware program that is promoted through the use of Trojans, browser hijackers and other similar malware. When your computer is infected with this bogus software, you will see many fake security alerts and notifications stating that your computer is infected. While running, Win 7 Home Security 2012 will supposedly scan your computer and display a variety of infections that won't be removed unless you first purchase the program. The scan results are false, you can safely ignore them. The same could be said about fake system security alerts, you should ignore them too:

Win 7 Home Security 2012 Firewall Alert
XP Home Security 2012 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.

Win 7 Home Security 2012 Alert
Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
– Dangerous code found in this site’s pages which installed unwanted software into your system.
– Suspicious and potentially unsafe network activity detected.
– Spyware infections in your system
– Complaints from other users about this site.
– Port and system scans performed by the site being visited.

Things you can do:
– Get a copy of Vista Security 2012 to safeguard your PC while surfing the web (RECOMMENDED)
– Run a spyware, virus and malware scan
– Continue surfing without any security measures (DANGEROUS)

Malware Intrusion
Sensitive areas of your system were found to be under attack. Spy software attack or virus infection possible. Prevent further damage or your private data will get stolen. Run an anti-spyware scan now. Click here to start.

To make things even worse, Win 7 Home Security 2012 will hijack Internet Explorer so that you will be constantly redirected to various misleading websites that promote malicious software or display misleading online ads. The rogue application will also block security related websites and antivirus software to protect itself form being deleted. As you can see, program is nothing more but a scam. Please use the removal guide below to remove Win 7 Home Security 2012 from your PC as soon as possible. To help the removal, enter these registry codes: 2233-298080-3424, 3425-814615-3990 or 9443-077673-5028 to make the virus think you have purchased the program. Additionally, use a reputable anti-spyware and delete all the files that beling to Win 7 Home Security 2012.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Win 7 Home Security 2012 you agree to our privacy policy and agreement of use.
do it now!
Reimage (remover) Happiness
Reimage (remover) Happiness
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Win 7 Home Security 2012. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.
Press mentions on Reimage

Win 7 Home Security 2012 manual removal:

Kill processes:
ppn.exe, agn.exe or similar randomly named 3 letter processes

Delete registry values:
HKEY_USERS.DEFAULTSoftwareMicrosoftInternet ExplorerBrowserEmulation "TLDUpdates" = '1'

HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand "(Default)" = '"%LocalAppData%kdn.exe" -a "%1" %*'

HKEY_CURRENT_USERSoftwareClassesexefileshellopencommand "(Default)" = '"%LocalAppData%kdn.exe" -a "%1" %*'

HKEY_CLASSES_ROOT.exeshellopencommand "(Default)" = '"%LocalAppData%kdn.exe" -a "%1" %*'

HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand "(Default)" = '"%LocalAppData%kdn.exe" -a "C:Program FilesMozilla Firefoxfirefox.exe"'

HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellsafemodecommand "(Default)" = '"%LocalAppData%kdn.exe" -a "C:Program FilesMozilla Firefoxfirefox.exe" -safe-mode'

HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetIEXPLORE.EXEshellopencommand "(Default)" = '"%LocalAppData%kdn.exe" -a "C:Program FilesInternet Exploreriexplore.exe"'

HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "AntiVirusOverride" = '1'

HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "FirewallOverride" = '1'

Delete files:





About the author

Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions

  • Rohwer3

    I had this same virus but instead of ppn.exe it was under EIO.exe. Might be a 3 letter executable that it installs randomly.

    • CPC

      I got this virus too, but mine used rys.exe

  • Richard

    I agree with poster 1, on my system the executeable was gaf.exe, so look for a three letter executeable.

  • David M.

    I could not remove this malware using the techniques or software above (but I also found the executable files were egl.exe and rmf.exe). my pc is running windows 7 and i was able to clean my computer by doing a system restore to a version that i knew was before i got this virus.

    • Irene

      I also have windows 7 and was able to get rid of this nasty parasite by restoring to a eariler date. I then ran a legit security scan to make sure it
      was totally gone.

    • By

      Got the same thing and just reset it to an earlier point. It worked

  • BJ

    Mine was xfs.exe

  • JFF

    I do agree with the 3-letter executable, but also look in the description of the process. If it is in Arabic, it is the virus. Also i cannot find the files i need to delete, help?

  • Robert

    exe file may also be named sty.exe

    Thank you for the removal instructions.

  • Noah

    It wont let me start security center now!
    And I cant find it under services. When I installed the virus it deleted 2 files! 🙁
    what now?

  • Digital4D

    Ive had this on 2 vista business machines and one windows 7 enterprise machine. Much like the other mentioned, the three letter naming system appears to be true. The last named version was “htp.exe.” Also, in some instances you may need to fix the class handler for .exes in the registry. An important similarity with each of these instances Ive found were that they all shared a common link to some resource of Windows Media Player, (direct show maybe but I forgot since the time of when I last worked on these issues, my apologies). The source of the windows 7 version I traced back to a rogue java temp package. Hope it helps!

  • sushi

    iyi.exe the bast*rd

  • oleg

    I got infected nad hijacked about 30 min ago, when all else failed, i used stytem restore to flush it out of my computer, and a VERY IMPORTANT NOTE: you CAN run certain antivirus programs by selecting them and clicking “run as administrator”

    • CPC

      Thanks. Ill try that.

  • George moss

    I got set up with this fake win 7 home security. And I need help removing it

  • George moss

    I got set up with this fake win 7 home security. And I need help removing it

  • SHOman97

    Spybot search and destroy

  • PHD

    Thanks all for your help.. it saved my time.. in my case the process was named “awg.exe” please do check for the 3 letter executables and ensure to remove of luck..:)

  • Patrick

    It will not let me delete the registry files. It says “Unable to delete all specified value”
    Please help ASAP.

  • Vicky

    Ive got it too but it wont even let me get on the internet…I had to use my laptop just to search for what to do. Im trying the system restore now. Well see in a few minutes……..yes, it worked. Now to get some good virus protection. That scared me.

  • Katie

    Help I cannot get on the internet and my it wont system restore. The stupid fake win 7 security keeps popping up~ dont know what to do?

  • jim

    I restored my system and it removed potential problem. thanks

  • dave

    Same as Katie help

  • Brian

    If you already have MalwareBytes installed, but are not able to execute it, because the Win 7 Home Security app pops up try the following:
    1. Boot into Safe Mode.
    2. Expect the Win 7 virus app to pop up there
    3. Goto Start -> Program Files-> MalwareBytes, but RIGHT-CLICK, and choose th Run As Administrator option.

    You should be able to update and run MalwareBytes successfully.
    It found the viruses and removed them successfully.

    I then restarted, and I am back in Windows 7 normal again with no issues.

    Good Luck!

  • Jen

    Just had this stupid rogue installed without my permission and now it is wreaking havoc; it wont even let me turn my computer ON (it shuts down on its own). I am trying to use the Startup Repair tool since the computer wont turn on otherwise… What a pain… Any suggestions?

  • K.M.

    I ended up with this on Christmas eve. Such a pain. Luckily I found out you could do the uninstaller. Ran microsoft home essentials scan and ended up doing a system restore to remove it all finally. The system restore was finally took care of it. Luckily my hubby is avid about backing up our pc so I have a restore from less than 24 hours ago.

  • Jenn

    Thank you everyone for all your help. I am running Malware Bytes now using your advice to run as administrator. Hopefully it works!

  • Bryan

    Ive located the source of the virus as cgn.exe , and Ive deleted it. However, my computer still has limited functionality. I am unable to run the Registry Editor, and cannot open any of the Anti-Spyware software. Ive tried using System Restore, and thats even blocked too!


  • pete

    my files were kwm.exe and sph.exe

  • AVB

    My files were ebs.exe and 713.exe

  • Carrie

    I had this horrible thing but since I had malwarebytes on my computer and it still wouldnt work because of the pop ups, I just right clicked on it And pressed run as administrator and it worked.