Win 7 Home Security is a counterfeit software that spreads with the help of Trojans, flash updates, browser hijackers and other similar methods. The program imitates a scan using its fake scanner and displays several infections. In reality, this rogue software is a useless software and can’t detect anything.
This program is very malicious and changes many security settings of your computer. It will disable all software programs on your computer and when you’ll run any of them; it will start doing a fake scan automatically. It will also show bogus security alerts very frequently and try to frustrate you. Here is a screenshot of rogue doing a fake scan:
Win 7 Home Security 2012 will repeatedly show you warnings, system tray alerts, fake pop-ups and try to trick you into purchasing full version of the software. You’ll be assured that full version of rogue software is really helpful, but in reality there is no different between full version and trial version. This software is just trying to get your money by scaring you with such alerts:
System danger!
Your system security is in danger. Privacy threats detected. Spyware, key loggers or Trojans may be working the background right now. Perform an in-depth scan and removal now, click here.
Malware Intrusion
Sensitive areas of your system were found to be under attack. Spy software attack or virus infection possible. Prevent further damage or your private data will get stolen. Run an anti-spyware scan now. Click here to start.
Don’t pay attention to this software and remove it from your computer as soon as possible.
How To Remove Win 7 Home Security 2012
These two methods can help you with removing the rogue software. Take a look at both methods and choose one depending on your expertise level with computers.
A) Automatic Removal
Win 7 Home Security 2012 is very stubborn to go out your computer and creates its files at various places. It also applies hidden attributes to all its files so that you can’t find them easily. To save you from all the possible headaches, we highly recommend automatic removal method.
This method requires you to download Spyware Doctor which is a very powerful Spyware Remover. You can download it by clicking the button below:
After downloading the software, please update its virus database and then perform a Full Scan of infected computer. Spyware Doctor will screen each file and find out infected files automatically. No matter where this rogue is creating its files, they all will be caught.
Once the scan is complete, click “Fix Checked” button and everything should be back to normal. Here is a video from our research lab showing how we remove this rogue software easily:
B) Manual Removal
Manual removal is risky, time consuming and doesn’t guarantee results opposed to automatic removal. This method suites only to computer geeks and If you are not aware of how to edit the registry, how to use task manager, things can be more difficult for you.
You can follow this method If you want but If you are not confident, consider using automatic removal method instead:
1. Restore Your Computer’s System To Earlier Date
System Restore is the first step when you are trying to remove Win 7 Home Security 2012. System Restore is meant to restore your computer’s setting to an earlier date when It was virus free.
More Help on Doing a System Restore
Please boot up your computer in “Safe Mode with Networking” mode (Keep pressing F8 button at startup and select this mode) and then click on Start—>Programs—>Accessories—>System Tools—>System Restore
Follow the easy instructions showing on System Restore wizard thereon.
2. Enter Activation Key In the Software To Fool It
If System Restore doesn’t work as expected, please try entering one of these registration keys in the fake software:
2233-298080-3424 or 2233-298080-3424
These registration keys will not remove the rogue but reduce its malicious effect. Then It will be easy to remove the software from your PC.
3. Correct Registry Entries Using Windows Registry Editor
Run Registry Editor by clicking on Start—>Run, type “regedit” and click OK. Find these registry entries and repair them: (More Help on How To Use Registry Editor)
HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’
HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’
HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%Program Files%\Internet Explorer\iexplore.exe”‘Settings\Application Data\.exe” /START “%1? %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’
HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%Program Files%\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%Program Files%\Mozilla Firefox\firefox.exe” -safe-mode’
4. Delete Rogue Files Related To Malware
Now you should remove infected files related to the rogue software. Browse these folders and delete the malicious files. (More Help on How To Search and Delete Files)
During our testing, we discovered that the rogue software always creates its executable file with three letters. Therefore, specifically look for files which have three random letters in their name (e.g. cpq.exe)
%AllUsersProfile%\
%AppData%\Local\.exe
%AppData%\Local\
%AppData%\Roaming\Microsoft\Windows\Templates\
%Temp%\
Please keep in mind that rogue software creates files with random names. For this reason, it is not possible to list exact file names here. Please use your common sense to remove the rogue otherwise consider using automatic removal method.
