Posted: February 19, 2011

Vista Total Security 2011 is a rogue anti-spyware scanner that fakes being a useful anti-malware product while shutting down significant portions of your computer and barraging you with fake infection identifications. Vista Total Security 2011 can block websites, redirect your browser, prevent programs from functioning correctly, and create desktop alert messages with false information. This rogue security program is known for being difficult to remove if not fought off quickly, so keep your security settings high and be on the lookout for Vista Total Security 2011 so that you can remove it if it does slip past your defenses.

An Infection with Stealth and Disguises

Instead of being the independent and the individual product it tries to depict itself to be, Vista Total Security 2011 is one slight tweak to a broader rogue security product template. Here are a few of the other names this rogue security product can use to infect your computer: Live Security Platinum, Vista Anti-Spyware 2011, Vista Security 2011, Vista Internet Security 2011 and Vista Anti-Virus 2011. Vista Total Security 2011 may be found with the '2011' appellation or without it, and will cleverly alter the operating system portion of its name to match the operating system you're actually running.

Vista Total Security 2011 has been documented to be uploaded to otherwise innocent file-sharing sites, but its relatives also have their own malicious home websites. Even if you don't visit the 'wrong' website, you may acquire the Vista Total Security 2011 infection anyway, since it also uses trojan-based delivery methods.

How Vista Total Security 2011 Impairs Your Machine

Once you get past the many guises used by Vista Total Security 2011 for infiltration, its activities are fairly usual as far as rogue security products go. The primary symptom is simply an endless march of pop-up alert messages on your desktop and browser. Examples include the following:

Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site's pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system.
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.

Things you can do:
- Get a copy of Vista Total Security 2011 to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)

Security breach!
Beware! Spyware infection was found. Your system security is at risk. Private information may get stolen, and your PC activity may get monitored. Click for an anti-spyware scan.

System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or trojans may be working the background right now. Perform an in-depth scan and removal now, click here.

Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.

All of these errors and any others Vista Total Security 2011 provide are complete fabrications and can actually lead you to distrust totally innocent files or websites. Vista Total Security 2011 may use these to hijack your web browser through proxy server-based vulnerabilities, pushing you towards its own website. Even more dangerous is Vista Total Security 2011's ability to close programs that could successfully delete it and other malware, upgrading it from a simple nuisance into a serious security risk!

Buying Vista Total Security 2011 is the worst possible course of action, since you'll be giving your credit card information away to criminals. Instead, try using this key: '1147-175591-6550'. This free registration may cause the rogue security product to lower its defenses long enough for you to delete Vista Total Security 2011 and get things back to normal.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\t3e0ilfioi3684m2nt3ps2b6lru
    2 %AppData%\Local\[3 RANDOM LETTERS].exe
    3 %AppData%\Local\t3e0ilfioi3684m2nt3ps2b6lru
    4 %AppData%\Roaming\Microsoft\Windows\Templates\t3e0ilfioi3684m2nt3ps2b6lru
    5 %AppData%\t3e0ilfioi3684m2nt3ps2b6lru
    6 %Temp%\t3e0ilfioi3684m2nt3ps2b6lru
    7 %UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe
    8 %UserProfile%\Templates\t3e0ilfioi3684m2nt3ps2b6lru

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1' = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1'HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" - '"%1" %*'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"'HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.exe\DefaultIcon "(Default)" = '%1'HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CLASSES_ROOT\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\.exe\shell\runas\command "(Default)" = '"%1" %*'HKEY_CLASSES_ROOT\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\exefile "Content Type" = 'application/x-msdownload'HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CLASSES_ROOT\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\exefile\shell\runas\command "IsolatedCommand" = '"%1" %*'

Additional Information on Vista Total Security 2011

  • The following messages's were detected:
    # Message
    1 Attention: DANGER!
    ALERT! System scan for spyware, adware, trojans and viruses is complete.
    Vista Total Security 2011 detected 35 critical system objects.
    2 System danger!
    Your system is in danger. Privacy threats detected.
    Spyware, keyloggers or Trojans may be working in the
    background right now. Perform an in-depth scan and removal
    now, click here.
    3 Vista Total Security 2011 ALERT
    Internet Explorer alert. Visiting this site may pose a security threat to your system


