Home Malware Programs Rogue Anti-Spyware Programs Vista Internet Security 2011

Vista Internet Security 2011

Posted: November 16, 2010

Although its name implies safety for your computer, Vista Internet Security 2011 is, in reality, a hostile rogue security program that steals control of your web browser and shuts down real security applications to prevent its own removal. Vista Internet Security 2011 will use concerning warning pop-ups, Trojans and related malware threats to cover up its misdeeds, but you should be aware that any threats that Vista Internet Security 2011 alerts you are to aren't really on your PC. Deleting Vista Internet Security 2011 from your computer can (and should!) be done with relative speed, but you should use anti-malware software designed for it rather than trying to delete Vista Internet Security 2011 without help.

Vista Internet Security 2011 is More Hindrance Than Help for Your PC Security

Vista Internet Security 2011's name is far from stagnant – in fact, after infecting you through a Trojan or a browser exploit Vista Internet Security 2011 will make sure that its name is in the best possible position to confuse you into trusting Vista Internet Security 2011. Vista Internet Security 2011 accomplishes this by changing the prefix to suit your OS, and may also change the middle and suffix portions of its name. For example, Vista Internet Security 2011 is also known as XP Internet Security 2011, Win 7 Internet Security 2010, Vista Antispyware 2011 and Vista Antispyware 2010.

Looking past the mere name, Vista Internet Security 2011 will attack your PC in the following ways while you leave Vista Internet Security 2011 to do its dirty work:

  • Vista Internet Security 2011 may force your browser to use a proxy server, which allows Vista Internet Security 2011 to take control over where your browser goes on the web. In addition to having your homepage changed and redirected from search results to hostile sites, you may also see errors like the one below blocking safe sites:

    Internet Explorer alert. Visiting this site may pose a security threat to your system!
    Possible reasons include:
    - Dangerous code found in this site's pages which installed unwanted software into your system.
    - Suspicious and potentially unsafe network activity detected.
    - Spyware infections in your system
    - Complaints from other users about this site.
    - Port and system scans performed by the site being visited.

    Things you can do:
    - Get a copy of Vista Internet Security 2011 to safeguard your PC while surfing the web (RECOMMENDED)
    - Run a spyware, virus and malware scan
    - Continue surfing without any security measures (DANGEROUS)

  • If you manage to get to a site that offers anti-malware solutions for Vista Internet Security 2011, you may be unable to download these programs. Vista Internet Security 2011 is known for blocking and interrupting downloads that could be installation files for anti-virus scanners and similar software - you can avoid this by renaming the file into a generic one that Vista Internet Security 2011 will allow, such as 'iexplore.exe.'
  • Vista Internet Security 2011 may also stop various security applications from running. The most easily-detected victims of Vista Internet Security 2011 attack include anti-virus scanners and Windows system utilities like the Task Manager.
  • Finally, Vista Internet Security 2011 will slip itself into your startup routine by changing your Registry without your permission. This lets Vista Internet Security 2011 run and perform the above attacks whenever Vista Internet Security 2011 likes, even if you haven't given Vista Internet Security 2011 permission to do so.

Ignoring Vista Internet Security 2011's Bad Advice

Further complicating any attempts to deal with Vista Internet Security 2011 is the fact that Vista Internet Security 2011 will create many different errors and pop-ups as part of its scheme to convince you that Vista Internet Security 2011 is a legitimate program. You may see errors like these:

“Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue security software. Eliminate the infection safely, perform a security scan and deletion now.”

“Privacy Threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.”

“Vista Internet Security 2011 Firewall Alert!
Vista Internet Security 2011 has blocked a program from accessing the Internet.
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen. Private data can be stolen by third parties, including credit card details and passwords.”

“Windows Security Center
Vista Internet Security 2011 reports that it is currently turned off. A firewall helps to protect your computer from potentially harmful content on the Internet. Click Recommendations to learn how to fix this problem.”

System Hijack!
System security threat was detected. Viruses and/or spyware may be damaging your system now. Prevent infection and data loss or stealing by running a free security scan.

System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or Trojans may be working the background right now. Perform an in-depth scan and removal now, click here.

Security breach!
Beware! Spyware infection was found. Your system security is at risk. Private information may get stolen, and your PC activity may get monitored. Click for an anti-spyware scan.

Avoid taking Vista Internet Security 2011's advice and purchasing a registration key to reduce occurrences of these problems. Letting even a registered version of Vista Internet Security 2011 remain on your PC is still a considerable security risk! However, you may want to try registering Vista Internet Security 2011 with the code '1147-175591-6550,' if only to reduce the frequency of its attacks.

Removing Vista Internet Security 2011 can also be expedited by using a Safe Mode boot to run system scans with the appropriate anti-malware programs. Safe Mode can be used by hitting F8 during startup prior to Windows loading, and will let you take steps to remove Vista Internet Security 2011 without the malware throwing any wrenches into your plans.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\AppData\Local\MSASCui.exe
    2 %UserProfile%\AppData\Local\opRSK
    3 %UserProfile%\AppData\Local\pw.exe
    4 %UserProfile%\Local Settings\Application Data\MSASCui.exe
    5 %UserProfile%\Local Settings\Application Data\opRSK
    6 %UserProfile%\Local Settings\Application Data\pw.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*HKEY_CURRENT_USER\Software\Classes\pezfileHKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-modeHKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*HKEY_CLASSES_ROOT\pezfileHKEY_CLASSES_ROOT\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*

Additional Information on Vista Internet Security 2011

  • The following messages's were detected:
    # Message
    1 Internet Explorer alert. Visiting this site may pose a security threat to your system!
    Possible reasons include:
    - Dangerous code found in this site?s pages which installed unwanted software into your system.
    - Suspicious and potentially unsafe network activity detected.
    - Spyware infections in your system
    - Complaints from other users about this site.
    - Port and system scans performed by the site being visited.
    Things you can do:
    - Get a copy of Vista Internet Security 2011 to safeguard your PC while surfing the web (RECOMMENDED)
    - Run a spyware, virus and malware scan
    - Continue surfing without any security measures (DANGEROUS)

    Vista Internet Security 2011 Firewall Alert
    Vista Internet Security 2011 has blocked a program from accessing the internet
    Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
    Private data can be stolen by third parties, including credit card details and passwords.

    Stealth intrusion!
    Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.

Loading...