XP Total Security 2012

By Domesticus in Rogue Anti-Spyware Program

XP Total Security 2012 is a program that will blackmail a computer user. Much like a thug that makes people "pay for protection" after going to their house and breaking their windows, XP Total Security 2012 will get into your computer, make all kinds of unwanted changes, become a constant and harmful annoyance, and then charge you to get rid of the "security threats" XP Total Security 2012 found. Most of the time, the only real security threat on your computer is XP Total Security 2012 itself. This program is part of a family of harmful software that changes names and skins, depending on your operating system. If a user is running Windows 7 or Windows Vista, then the name of this program will change accordingly.

What is the Purpose of XP Total Security 2012?

You may ask yourself why someone would want to fill your computer with annoying pop-ups and fake virus warnings. The purpose of most of these rogue anti-spyware programs is to scare users and collect money. By making a user think that their computer is filled with viruses, and that XP Total Security 2012 is a legitimate security program, the makers of these kinds of programs scam computer users into entering their credit card information to get a license for XP Total Security 2012. Paying for the license does nothing. If you entered your credit card information, call your credit card company to stop the charges. These programs bundled with a Trojan can be quite harmful, since they can block key folders on your computer, and even your access to the Internet. XP Total Security 2012 has been known to redirect users constantly to websites requesting that the user purchase a useless XP Total Security 2012 license.

Special Steps for Removing XP Total Security 2012

The best way to remove any rogue anti-spyware program is by using legitimate anti-virus and anti-malware tools. However, there are some special steps that need to be taken when removing XP Total Security 2012, or any of the malicious programs that form a part of XP Total Security 2012's family of harmful software.

- Enter manual registration and use a registration key to get rid of most of the XP Total Security 2012 pop-up windows and alerts. Remember, this does not remove the program, but will temporarily remove annoying alerts and other problems, so that you can have normal access to your computer and to the Internet. A registration key that has been known to work is 1147-175591-6550.

- Change the system date a week ahead. After you reset your computer, change it back. If this works, you may now have access to your folders and task manager to get started with manual removal of XP Total Security 2012.

- If you have access to your Task Manager, stop all executable processes with three-letter names.

What Makes XP Total Security 2012 Dangerous?

Even if you don't fall for the trick of paying for protection, XP Total Security 2012 is still dangerous to your system. Some of the things that make XP Total Security 2012 a threat are that:

- XP Total Security 2012 can propagate and update itself without authorization.

- XP Total Security 2012 will use malware and Trojans to download itself into your computer.

- XP Total Security 2012 can jeopardize your personal information and poses a significant security risk.

File System Details

XP Total Security 2012 may create the following file(s):
# File Name Detections
1. %UserProfile%\AppData\Local\MSASCui.exe
2. %UserProfile%\Local Settings\Application Data\MSASCui.exe
3. %UserProfile%\AppData\Local\vz.exe
4. %UserProfile%\Local Settings\Application Data\vz.exe
5. %UserProfile%\AppData\Local\pw.exe
6. %UserProfile%\Local Settings\Application Data\pw.exe
7. %UserProfile%\Start Menu\Programs\XP Total Security 2012.lnk
8. %UserProfile%\Desktop\XP Total Security 2012.lnk
9. %UserProfile%\Local Settings\Application Data\opRSK
10. %AllUsersProfile%XP Total Security 2012
11. %UserProfile%\AppData\Local\opRSK

Registry Details

XP Total Security 2012 may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%Program Files%\Mozilla Firefox\firefox.exe"'
HKCR\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKCR\pezfile
HKLM\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%Program Files%\Mozilla Firefox\firefox.exe" -safe-mode'
HKCR\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\vz.exe" /START "%1" %*
HKCU\Software\Classes\pezfile
HKLM\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1"
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" – '"%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%Program Files%\Internet Explorer\iexplore.exe"'
HKCR\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\vz.exe" /START "%1" %*
HKCR\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKCU\Software\Classes\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\vz.exe" /START "%1" %*

Messages

The following messages associated with XP Total Security 2012 were found:

Critical Warning!
Critical System Warning! Your system is probably infected with a version of Trojan-Spy.HTML.Visafraud. This may result in website access passwords being stolen from Internet Explorer, Mozilla Firefox, Outlook etc. Click Yes to scan and remove threats. (recommended)
Security Alert!
Your computer is being attacked from a remote machine!
Block Internet access to your computer to prevent system infection.
System warning!
Continue working in unprotected mode is very dangerous. Viruses can damage your confidential data and work on your computer. Click here to protect your computer.
System warning!
Security Essentials Ultimate Pack software detects programs that may compromise your privacy and harm your systems. It is highly recommended you scan your PC right now. Click here to start.

Trending

Most Viewed

Loading...