Title: XP Home Security 2012 Also known as: XPHomeSecurity2012
Type: Spyware
Severity scale:  (67 / 100)

XP Home Security 2012 is a rogue anti-spyware program that simulates a system scan and reports false scan results just to scare you and make you think that your computer is infected with Trojans, worms and other malware. Once installed, it will display fake security alerts or notifications and then inform you that you need to pay money to register the program if you want to remove the infections and computer threats, which of course do not even exist. Do not pay for this software and get rid of XP Home Security 2012 form your computer upon detection using the removal stated guide below.

XP Home Security 2012 displays warnings and notifications about serious security threats and privacy issues. It will also state that it has detected many critical spyware objects and that these objects can expose private information. Of course, that’s not true. This is just a part of whole scam. Besides, no matter what you decide to do, it will ask to pay for a full version of the program to protect your computer from malware and possible attacks from the Internet. Just ignore all of this and read the removal instructions carefully. Remove XP Home Security 2012 as soon as possible!

Automatic XP Home Security 2012 removal:

XP Home Security 2012 manual removal:

Kill processes:

Delete registry values:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates” = ‘1’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “%1” %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ‘1’

Delete files:
%AllUsersProfile%\Application Data3f7pnvfncsjk2e86abfbj5h %LocalAppData%\kdn.exe %LocalAppData%3f7pnvfncsjk2e86abfbj5h %Temp%3f7pnvfncsjk2e86abfbj5h %UserProfile%\Templates3f7pnvfncsjk2e86abfbj5h

