OpenCloud Security

  • Name(s): OpenCloud Security, Open Cloud Security
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove OpenCloud Security and Do Not Purchase The Full Version of This Program as This is a Scam To Steal Your Money

    DOWNLOAD SPYWARE DOCTORFor Removal of OpenCloud Security


close

Warning: OpenCloud Security is a dangerous malware that must be remove immediately

What is OpenCloud Security?

OpenCloud Security is a virus known as Rogue Antivirus. It is a malware program that is designed to mimic actual security programs in order to trick its victims in to buying its full version. OpenCloud Security performs fake scans and issues false alerts that inform you that your PC is infected with a number of bogus viruses. Please understand that everything this program tells you is a complete lie. The purpose of OpenCloud Security is to scare you in to buying its full version, and it will try every trick in the book to try and convince you to pay for its full version. Please do not fall for this scam. We highly recommend that you use one of the following methods to remove this threat once and for all:

OpenCloud Security Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block OpenCloud Security from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find OpenCloud Security
  • Press Fix Checked to remove OpenCloud Security

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove OpenCloud Security, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


<random characters.exe>

Delete the following files and folders:


All UsersApplication Data< random characters.exe >

Delete the following registry entries:


HKEY_CURRENT_USER..<random characters.exe>


Security Sphere 2012

  • Name(s): Security Sphere 2012
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Security Sphere 2012 and Do Not Purchase The Full Version of This Program as This is a Scam To Steal Your Money

    DOWNLOAD SPYWARE DOCTORFor Removal of Security Sphere 2012


close

Warning: Security Sphere 2012 is a dangerous malware that must be remove immediately

What is Security Sphere 2012?

Security Sphere 2012 is the latest Rogue Antivirus program to hit the web. A Rogue Antivirus programs such as Security Sphere 2012 are a form of malware with the sole purpose of scamming its victims for money. Security Sphere 2012 is commonly spread with the use of attack sites, and installs on your computer without your knowledge. Once installed it will just pop up and start alerting you that your computer is infected with viruses, and in order to remove these viruses you must purchase the full version of this program. Please note that the scans and the alerts are completely false. This program is designed to take your computer over for ransom until your purchase its full version. It will try its very best to persuade you to buy in to this scam. Do not purchase this program. I repeat do not purchase this program! We have tested out the following removal method that has successfully removed Security Sphere 2012 once and for all.

Security Sphere 2012 Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block xxxx from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find xxxx
  • Press Fix Checked to remove xxxx

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Security Sphere 2012, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:

<random characters.exe>

Delete the following files and folders:


All UsersApplication Data< random characters.exe >

Delete the following registry entries:


HKEY_CURRENT_USER..<random characters.exe>


PC Security Pro

  • Name(s): PC Security Pro
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove PC Security Pro and Do Not Purchase The Full Version of This Program as This is a Scam To Steal Your Money

    DOWNLOAD SPYWARE DOCTORFor Removal of PC Security Pro


close

Warning: PC Security Pro is a dangerous malware that must be remove immediately

What is PC Security Pro?

PC Security Pro is a spyware threat that is classified as a fake antivirus. It is being spread on the internet via attack sites, and infects its victim’s computer without their knowledge. Once infected PC Security Pro will pop up and conduct a fake virus scan. After the scan it will inform you that your computer is infected with various viruses, and in order to remove these infections you must purchase the full version of PC Security Pro. Beware that this is only a trick to steal your money. The Scan is FAKE, the infections it claims to find are FAKE, and this truth is PC Security Pro itself is a virus! Do not purchase the full version of this program. In case you fell victim to this scam and purchased the full version of PC Security Pro you should contact your credit card company immediately. Please follow these instructions below in order to remove this threat from your PC.

PC Security Pro Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block PC Security Pro from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find PC Security Pro
  • Press Fix Checked to remove PC Security Pro

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove PC Security Pro, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


<random characters.exe>

Delete the following files and folders:


All UsersApplication Data< random characters.exe >

Delete the following registry entries:


HKEY_CURRENT_USER..<random characters.exe>


Security Protection

  • Name(s): Security Protection
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Security Protection and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTORTo Remove of Security Protection


close

Warning: Security Protection is a dangerous malware that must be remove immediately

What is Security Protection?

Security Protection is a type of malware which camouflages itself as an antivirus program. This type of malware is known as a rogue application. Security Protection was created by hackers to make money off of you. Security Protection will try its hardest to get you to purchase the full version of Security Protection by displaying fake virus scan results and alerts that will state that you have viruses on your computer. Hackers want you to believe that Security Protection is a real antivirus program and that all the threats it is displaying are real. Don’t fall victim to this scam, Security Protection is a malware and you should remove it from your computer. Besides the constant popups and notifications, Security Protection also controls vital system functions and will block you from running your computer programs. It is very important you follow the removal steps below and rid your computer of this nasty malware.

Security Protection Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Security Protection from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Security Protection
  • Press Fix Checked to remove Security Protection

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Security Protection, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


[random characters].exe

Delete the following files and folders:


%Documents and Settings%All UsersApplication Data[random characters]

Delete the following registry entries:

HKEY_CURRENT_USERSoftwareZentomSystemGuard
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “[random characters].exe”


Zentom System Guard

  • Name(s): Zentom System Guard
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Zentom System Guard and Do not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTORFor Removal of Zentom System Guard


close

Warning: Zentom System Guard is a dangerous malware that must be remove immediately

What is Zentom System Guard?

Zentom System Guard is a type of malware which camouflages itself as an antivirus program. This type of malware is known as a rogue application. Zentom System Guard was created by hackers to make money off of you. Zentom System Guard will try its hardest to get you to purchase the full version of Zentom System Guard by displaying fake virus scan results and alerts that will state that you have viruses on your computer. Hackers want you to believe that Zentom System Guard is a real antivirus program and that all the threats it is displaying are real. Don’t fall victim to this scam, Zentom System Guard is a malware and you should remove it from your computer. Besides the constant popups and notifications, Zentom System Guard also controls vital system functions and will block you from running your computer programs. It is very important you follow the removal steps below and rid your computer of this nasty malware.

Zentom System Guard Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Zentom System Guard from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Zentom System Guard
  • Press Fix Checked to remove Zentom System Guard

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Zentom System Guard, and automatically protect you against any future malware attacks.

Manual Removal

Stop the following Processes:


[random characters].exe

Delete the following files and folders:


%Documents and Settings%All UsersApplication Data[random characters]

Delete the following registry entries:

HKEY_CURRENT_USERSoftwareZentomSystemGuard
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “[random characters].exe”


Anti Malware Lab

  • Name(s): Anti-Malware Lab
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Anti-Malware Lab and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTORFor Removal of Anti-Malware Lab


close

Warning: Anti-Malware Lab is a dangerous malware that must be remove immediately

What is Anti-Malware Lab?

Is Anti-Malware Lab popping up on your computer? If so, then your computer is infected with a very dangerous malware known as a rogue antivirus program. Programs like Anti-Malware Lab infect host computers and mimic an antivirus program. Anti-Malware Lab will try to convince you that it is an antivirus program and that your computer is infected with many Trojans and viruses. All of virus scans, popups and alerts from Anti-Malware Lab are all false. Anti-Malware Lab has manipulated your system in an attempt to scare you into purchasing the full version of Anti-Malware Lab. It is strongly advised that you do not purchase the full version of Anti-Malware Lab, this malware is created by hackers and you do not want to provide them with your credit card information. Instead, follow the instructions below and remove Anti-Malware Lab and protect your computer in the future.

Anti-Malware Lab Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Anti-Malware Lab from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Anti-Malware Lab
  • Press Fix Checked to remove Anti-Malware Lab

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Anti-Malware Lab, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


<random characters.exe>

Delete the following files and folders:


%Documents and Settings%All UsersApplication Data[random characters]


Win 7 Security 2012

  • Name(s): Win 7 Security 2012, Win 7 Home Security, Win 7 Internet Security
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Win 7 Security 2012 and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTOR or call: (800) 884-8437For Removal of Win 7 Security 2012


close

Warning: Win 7 Security 2012 is a dangerous malware that must be remove immediately

What is Win 7 Security 2012?

Win 7 Security 2012, Win 7 Home Security 2012 and Win 7 Internet Security 2012 are all names of the same malware. This form of malware is known as rogue antivirus. The purpose of Win 7 Security 2012 is to silently download into its victim’s computer without their knowledge, and take their computer for ransom. Once infected with Win 7 Security 2012 it will prevent you from launching any programs, and show fake virus scans with false alerts. It asks you purchase the full version of Win 7 Security 2012 to remove the viruses it claims it has found. Beware: this a scam to get your money. This program will try its best to persuade you to buy its full version, and you use every scare tactic in its playbook to convince you that there is something really wrong with your system. Please understand that the only threat to your computer is Win 7 Security 2012 itself as it is malware created by hackers to steal your money. Follow these instructions below to remove Win 7 Security 2012:

Important: If this virus has hijacked your PC it could prevent you from launching any programs; Download win7-fix.zip then double-click the .reg file inside. This will disable the hijack by restoring your registry settings back to normal. Then proceed with the removal instructions below:

Win 7 Security 2012 Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Read this if you are still not able to download
    Win 7 Security 2012 will block off access to all programs except for your web browser. In order to get around it you must save the Spyware Doctor installation file as explorer.exe when downloading. Try one of the following methods:
    • Type: http://www.disablemalware.com/download/sd/explorer.exe directly into Internet Explorer and save the file to your desktop
    • Click the Window’s Start button located at the bottom left corner then type: http://www.disablemalware.com/download/sd/explorer.exe and press Enter then save the file to your desktop
    • Download this file to a clean PC then transfer it over to the infected PC via USB drive. Make sure you have renamed the file to explorer.exe

    In order to install Spyware Doctor you must right-click on the explorer.exe file then select Run as administrator. Do step #3 if you are unable to install

  • Restart in Safe Mode with Networking
    How To Restart In Safe Mode With Networking 
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Win 7 Security 2012 from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor (right-click on the file then select Run as administrator)
  • Once Installed, you must update its definitions by clicking Smart Update
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Win 7 Security 2012
  • Press Fix Checked to remove Win 7 Security 2012

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Win 7 Security 2012, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


[random characters.exe]

Delete the following files and folders:


%AllUsersProfile%[random characters]
%LocalAppData%ppn.exe
%LocalAppData%[random characters]
%Temp%[random characters]
%AppData%Templates[random characters]

Delete the following registry entries:


HKEY_CLASSES_ROOT.exeshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_CLASSES_ROOTexefileshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe”‘
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetFIREFOX.EXEshellsafemodecommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe” -safe-mode’
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetIEXPLORE.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Internet Exploreriexplore.exe”


Vista Security 2012

  • Name(s): Vista Security 2012, Vista Home Security, Vista Internet Security
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Vista Security 2012 and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTOR or call: (800) 884-8437For Removal of Vista Security 2012


close

Warning: Vista Security 2012 is a dangerous malware that must be remove immediately

What is Vista Security 2012?

Vista Security 2012, Vista Home Security 2012 and Vista Internet Security 2012 are different names of the same malware. This malware spreads through the internet via attack websites, and downloads itself on to its victim’s computer without their knowledge. Once installed Vista Security 2012 will show false alters and false virus scans all claiming that your computer is infected with various infections, and in order to remove these infections you must purchase the full version of Vista Security 2012. Please understand that this is only all a trick to steal your money. The virus scans and alerts are bogus. The only real threat to your computer is Vista Security 2012 itself as this program was created by cyber criminals to scam innocent people for money. This virus will also change your internet settings thus will make it impossible to surf the web. You’ll need to Restore Your Internet Connection(read below) in order is remove this virus. Follow our instructions below to remove Vista Security 2012 once and for all.

Vista Security 2012 Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Vista Security 2012 from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Vista Security 2012
  • Press Fix Checked to remove Vista Security 2012

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Vista Security 2012, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


[random characters.exe]

Delete the following files and folders:


%AllUsersProfile%[random characters]
%LocalAppData%ppn.exe
%LocalAppData%[random characters]
%Temp%[random characters]
%AppData%Templates[random characters]

Delete the following registry entries:


HKEY_CLASSES_ROOT.exeshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_CLASSES_ROOTexefileshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe”‘
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetFIREFOX.EXEshellsafemodecommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe” -safe-mode’
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetIEXPLORE.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Internet Exploreriexplore.exe”


XP Security 2012

  • Name(s): XP Security 2012, XP Home Security, XP Internet Security
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove XP Security 2012 and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTOR or call: (800) 884-8437To Remove XP Security 2012


close

Warning: XP Security 2012 is a dangerous malware that must be remove immediately

What is XP Security 2012?

XP Security 2012, XP Home Security 2012 and XP Internet Security 2012 are all strands of the same malware. This type of malware is commonly refered to as rogue antivirus programs. Rogue programs like XP Security 2012 are created with the intent to trick and trap innocent computer. As many of you have figured out by now, XP Security 2012 is not a real antivirus program. All of the notifications, popups, virus scans and alerts from XP Security 2012 that claim your computer is infected with viruses are all false. You should disregard any and all claims made by XP Security 2012. All of these false claims are a type of scare tactic to lure innocent computer users to pay for the full version of XP Security 2012. Please keep in mind that XP Security 2012 is a malware program created by computer hackers. Do not provide any money to XP Security 2012. Instead, follow the removal instructions below to remove XP Security 2012 and keep your computer protected in the future.

Important: If this virus has hijacked your PC it could prevent you from launching any programs; Download win-xp-fix.zip then double-click the .reg file inside. This will disable the hijack by restoring your registry settings back to normal. Then proceed with the removal instructions below:

XP Security 2012 Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Read this if you are still not able to download
    XP Security 2012 will block off access to all programs except for your web browser. In order to get around it you must save the Spyware Doctor installation file as explorer.exe when downloading. Try one of the following methods:
    • Type: http://www.disablemalware.com/download/sd/explorer.exe directly into Internet Explorer and save the file to your desktop
    • Click the Window’s Start button located at the bottom left corner and select Run then type: http://www.disablemalware.com/download/sd/explorer.exe and press Enter then save the file to your desktop
    • Download this file to a clean PC then transfer it over to the infected PC via USB drive. Make sure you have renamed the file to explorer.exe

    In order to install Spyware Doctor you must right-click on the explorer.exe file then select Run as administrator. Do step #3 if you are unable to install

  • Restart in Safe Mode with Networking
    How To Restart In Safe Mode With Networking 
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block XP Security 2012 from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor (right-click on the file then select Run as administrator)
  • Once Installed, you must update its definitions by clicking Smart Update
  • Press Scan Now to start scanning
  • After Scan is complete, it should find XP Security 2012
  • Press Fix Checked to remove XP Security 2012

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


[random characters.exe]

Delete the following files and folders:


%AllUsersProfile%Application Data[random characters]
%LocalAppData%kdn.exe
%LocalAppData%[random characters]
%Temp%[random characters]
%UserProfile%Templates[random characters]

Delete the following registry entries:


HKEY_CLASSES_ROOT.exeshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_CLASSES_ROOTexefileshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%1? %*’
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe”‘
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetFIREFOX.EXEshellsafemodecommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Mozilla Firefoxfirefox.exe” -safe-mode’
HKEY_LOCAL_MACHINESOFTWAREClientsStart Menu InternetIEXPLORE.EXEshellopencommand “(Default)” = ‘”%UserProfile%Local SettingsApplication Data[random characters].exe” /START “%Program Files%Internet Exploreriexplore.exe”


Windows 7 Recovery

  • Name(s): Windows 7 Recovery
  • Class: Rogue Antivirus, Trojan
  • Symptoms: Fake Virus Scans, Popups, Browser Hijack, Reduced PC Performance
  • Recommendation: Immediately Remove Windows 7 Recovery and Do Not Purchase The Full Version of This Program. It is A Scam To Steal Your Money.

    DOWNLOAD SPYWARE DOCTORFor Removal of Windows 7 Recovery


close

Warning: Windows 7 Recovery is a dangerous malware that must be remove immediately

What is Windows 7 Recovery?

Windows 7 Recovery is a malware classified as a rogue system optimizer. Once installed on your computer, Windows 7 Recovery sets itself to automatically start with Windows.  It creates havoc in your computer by doing false scans and alerts.  It displays false errors every time you try to launch a program, and tries its best to convince you there is something really wrong with your computer.  It tells you to purchase the full version of the Windows 7 Recovery in order to get rid of all the errors. The purpose of Windows 7 Recovery is to steal your money by convincing you to buy the full version of this program. Beware! Purchasing this program means that you are falling victim to a Scam.  You can remove Windows 7 Recovery by following the removal methods mentioned below:

Windows 7 Recovery Removal Instructions

  • Download Spyware DoctorDownload Spyware Doctor (Save this file on your desktop) If you are unable to download – rename the file to explorer.exe then save, or save this file to a clean PC while renaming it to explorer.exe then copy it to the infected PC via USB Drive
  • Restart your PC in Safe Mode with Networking
    How To Restart In Safe Mode With Networking
    • Restart or turn On your computerSafe Mode with Networking
    • Start Pressing the F8 key repeatedly as PC boots up (Must do this before Windows launches)
    • On Windows Advance Boot Option Menu
    • Select Safe Mode with Networking
    • This will block Windows 7 Recovery from loading up and let you remove it using Spyware Doctor
  • Do the following in Safe Mode with Networking
  • Install Spyware Doctor
  • Once Installed, you must click Smart Update to download the latest updates
  • Press Scan Now to start scanning
  • After Scan is complete, it should find Windows 7 Recovery
  • Press Fix Checked to remove Windows 7 Recovery

  • Alternatively, you can Download STOPzilla and run a full Scan. STOPzilla has also performed very well in neutralizing this threat.

Please note that you will need to register Spyware Doctor in order to remove this infection. Once registered Spyware Doctor will remove Windows 7 Recovery, and automatically protect you against any future malware attacks.

close

If you need help with removing this malware or instaling Spyware Doctor call (800) 884-8437

Manual Removal

Stop the following Processes:


<random characters.exe>

Delete the following files and folders:


All UsersApplication Data< random characters.exe >

Delete the following registry entries:


HKEY_CURRENT_USER..<random characters.exe>