Description of Win 7 Antivirus 2012 and consequences of its residing on your Pt’s

Win 7 Antivirus 2012 is a self-praising program, but it arranges the whole affair as though it is a computer system that extols its virtues. For instance, there are several methods applied to download and install the program.
One of the most widespread techniques is a two steps introduction. First step includes introduction of a program responsible for popping up invitation to download and install Win 7 Antivirus 2012 with relevant link provided. Subject to the way it is downloaded, the above inviter is either trojan or worm. It is to be considered a part of the program. The invitation it displays is of   variable text, but  usually issued on behalf of a computer system and describes with admiration inexistent features of the program it prompts user to download and install.
The second step is a download of Win 7 Antivirus 2012 which is a fake system security tool and adware. The adware’s website displays numerous awards the program allegedly received from independent experts. Users are supposed to download the adware through its website as the above malware-inviter of trojan or worm type redirects them to it. However, the installation is completed without user’s agreement, if such is not provided,  in a concealed mode by the same malware that prompts users to install Win 7 Antivirus 2012  in line with standard system  rules of procedure.
Get rid of this nasty malware regardless of peculiarities of its installation, as it anyway keeps its annoying and indecent self praising routines after its delivery. Without exaggeration, every threat  reported by the adware is a lie and an act of self-praising. Also, that diverts user’s attention from real threats, which are very likely to exist  and to emerge while computer system is under false protection of the rogue antispyware.
Win 7 Antivirus 2012 Technical Details:

  • Full name: Win 7 Antivirus 2012, Windows 7 Antivirus 2012
  • Version: 2012
  • Type: Rogue anti-spyware
  • Origin: Russian Federation, EU

Signs of being infected with Win 7 Antivirus 2012

In addition to being quite annoying software, Win 7 Antivirus 2012 is quite dangerous as it is capable of disordering computer system and    disabling particular programs.
Fortunately, profusion of the adware signs of presence makes it possible to detect it without special tools and methods. The counterfeited system utility issues two types of messages in terms of obviousness of their relation to it. One type messages comprise occurrences of the adware name either in their body or caption or both whereas the another type messages  do not contain any such entry, neither in their body nor in the caption.   However, the former messages prevail and yet there is a graphic user’s interface of the malware which unmistakably proves that the program is installed.
However, it takes some time for users to arrive at conclusion that the program is malignant and that they need to remove Win 7 Antivirus 2012.
Win 7 Antivirus 2012 automatical removal:

Win 7 Antivirus 2012 infection on board hints at presence of real infections due to the lack of protection during the adware’s reign. Follow the link below to expose every threat, as well as disinfect computer system covering, of course, the issue of   Win 7 Antivirus 2012 removal.

Manual Removal of Win 7 Antivirus 2012:

Win 7 Antivirus 2012 is too loud, noisy and annoying to pass unnoticed so that its detection requires, basically, no special routine – quite unlike its extermination. To remove Win 7 Antivirus 2012 manually, please delete its components specified below and make sure   you have found the entries specified before deleting them, for it is a common oversight of users when they find and delete objects with similar names instead of the adware components. That certainly leads to the adware removal failure.

Remove Win 7 Antivirus 2012 files and dll’s:


Unregister Win 7 Antivirus 2012 registry values:

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates” = ‘1’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ‘1’

