How to remove XP Antivirus 2012

Wednesday, June 15th, 2011 at 3:21 am
Home » Rogue Antispyware » XP Antivirus 2012

XP Antivirus 2012 description

XP Antivirus 2012 is a deceptive application pretending to be a computer protection tool. The trojan based software starts its activities as soon as it is installed on your computer. It downloads itself automatically without user’s knowledge and consent.

Once active this fake program will set user’s mind that computer is infected with different types of malware and viruses through its fake alert messages. Do not fall for it because XP Antivirus 2012 is malicious and fraudulent. It is designed to pilfer money from unwary users. Ignore all fictitious security alerts but use decent spyware scanner and get rid of XP Antivirus 2012 as soon as possible.

XP Antivirus 2012 may be difficult to deal with since it loads tons of pop-ups. Enter 3425-814615-3990 for “registering” the fake program to render the rogue inactive. Once you stop the alerts, you can delete XP Antivirus without it interrupting.

XP Antivirus 2012 is a Rogue Antispyware software

How to manually remove XP Antivirus 2012

To remove XP Antivirus 2012 spyware you must block XP Antivirus 2012 sites, stop and remove processes, unregister DLL files, search and delete all other XP Antivirus 2012 files and registry utility. Follow the XP Antivirus 2012 detection and removal instructions below.

The most typical software removal method is to remove XP Antivirus 2012 by using "Add or Remove Programs" service. However there may be hidden XP Antivirus 2012 files, running processes and registries in your computer, so XP Antivirus 2012 may recreate all other files after reboot.

XP Antivirus 2012 manual removal instructions

Stop and remove XP Antivirus 2012 processes:
ppn.exe
kdn.exe
Read more how to kill XP Antivirus 2012 processes

Locate and delete XP Antivirus 2012 registry entries:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
Read more how to delete XP Antivirus 2012 registry entries
Download RegistryBooster 2010 to scan errors caused by XP Antivirus 2012

Detect and delete other XP Antivirus 2012 files:
%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H
%LocalAppData%\ppn.exe
%Temp%\U3F7PNVFNCSJK2E86ABFBJ5H
%LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H
%AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H
or
%AllUsersProfile%\Application Data\u3f7pnvfncsjk2e86abfbj5h
%LocalAppData%\kdn.exe
%LocalAppData%\u3f7pnvfncsjk2e86abfbj5h
%Temp%\u3f7pnvfncsjk2e86abfbj5h
%UserProfile%\Templates\u3f7pnvfncsjk2e86abfbj5h

We strongly recommend you to use spyware remover to track XP Antivirus 2012 and automaticaly remove XP Antivirus 2012 processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: , , ,

8 Responses to

XP Antivirus 2012

  1. Derrick B

    Or……
    1. Shut off your computer.
    2. Turn on computer and press F8 repeatedly until boot menu appears.
    3. Select start windows in safe mode option.
    4. When windows finishes loading, press start, all programs, accessories, system tools,
    system restore.
    5. System restore will give you a bunch of dates you can restore your computer to.
    Select a date before the virus was loaded into your computer.
    6. Computer will restore and reboot, and voila. No more virus.

    Worked for me using windows XP. Please note this will also eliminate any other programs that were installed prior to that date as well. You may have to re-install some items.

    Reply

    zach Reply:

    Safemode doesn’t work with new versions of this. For the computer I have that’s infected it runs a “tro.exe” and hooks the safe mode restore points also.

    Reply

    Raj Reply:

    IT WORKED. Thanks Derrick

    Reply

  2. Mike

    Yep, same here. I must have a more sophisticated ver as when I tried to boot into safe mode, it hooked it as well. Any ideas?

    Reply

  3. Steve

    If you have more than one account on your PC then open up another account in safe mode that is not infected. It will work. Then go to start->program->accessories->system tools->system restore. Set the date back to a date before the infection and restore.
    It worked for me. If you don’t have a second account on your PC it will be more difficult. Once you get it fixed always have at least 2 administrator accounts on your PCs.

    Reply

  4. Mike

    I did not even realize I had a second login account. I went into it and restored my system, went back only one day and problem solved!!!!! Thank you soooooo much!

    Mike

    Reply

  5. JohnC

    I can’t start in safe mode and only have one user set up. Any ideas? I only have one browser installled too. Is there something I can do through the run box?

    Reply

    Luciana Reply:

    Yes, you can run the Task Manager and kill malicious processes. Check the manual removal above.

    Reply

Leave a Reply

Download does not start? Try a mirror download here