Home Malware Programs Rogue Anti-Spyware Programs Win 7 Home Security

Win 7 Home Security

Posted: February 19, 2011

Win 7 Home Security is a spin-off of many other confirmed rogue security products such as XP Anti-Virus Pro 2010 and Vista Total Security 2011. While using a computer infected with Win 7 Home Security, you'll be interrupted by frequent error messages and other alerts that falsely indicate infections and redirect you towards Win 7 Home Security's website. You may also experience browser hijacking or a sudden lack of functionality in legitimate anti-malware software. This rogue security program can be a serious security risk as well as a way for crooks to steal your money, making deleting Win 7 Home Security a high-priority task.

Made from a Common Malicious Mold

Win 7 Home Security follows the standard template for rogue security products - it falsely detects infections and produces trumped up scanner results, and then uses heavy-handed means to force you to go to its website. The most immediate danger to your system is simply that you'll think Win 7 Home Security is a useful product or one that you can pay to go away, in which case you'll be giving your credit card information to criminals! If you see any of these error messages, your computer is almost certainly infected:

System Hijack!
System security threat was detected. Viruses and/or spyware may be damaging your system now. Prevent infection and data loss or stealing by running a free security scan.

System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or trojans may be working the background right now. Perform an in-depth scan and removal now, click here.

Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.

Security breach!
Beware! Spyware infection was found. Your system security is at risk. Private information may get stolen, and your PC activity may get monitored. Click for an anti-spyware scan.

Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.

Attention: DANGER!
ALERT! System scan for spyware, adware, trojans and viruses is complete.
Win 7 Home Security detected 30 critical system objects.

Related Infection Symptoms to Ward Off

Win 7 Home Security isn't content with just scaring you, however. More dangerously, it will also block software you need to maintain the integrity of your computer, as well as take over your web browser. The following error messages are ones you can expect to see from Win 7 Home Security and similar rogue programs with regards to these problems:

Win 7 Home Security Firewall Alert
Win 7 Home Security has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.

Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site's pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.

Things you can do:
- Get a copy of Win 7 Home Security to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)

Win 7 Home Security also goes by many alternate names, such as XP Total Security 2011, Vista Internet Security, Win 7 Anti-Spyware 2011 and Win 7 Home Security 2011. The latter variant has a known malicious domain at alucewyfyxut.com, while the Win 7 Home Security version has at least one site in place at avhide.com. Avoiding these websites and keeping suitable protective anti-malware software up at all times should help you evade needing to know how to delete Win 7 Home Security in the first place.

Due to Win 7 Home Security's ability to shut down security software and occasionally even bypass Safe Mode security parameters, you should remove Win 7 Home Security rapidly if you do suspect it or a similar rogue security product to be inhabiting your system. Under no circumstances should you purchase it, regardless of how difficult Win 7 Home Security is making things for your computer! Using the following free registration key may make removal simpler: '1147-175591-6550'.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\t3e0ilfioi3684m2nt3ps2b6lru
    2 %AppData%\Local\[3 RANDOM LETTERS].exe
    3 %AppData%\Local\t3e0ilfioi3684m2nt3ps2b6lru
    4 %AppData%\Roaming\Microsoft\Windows\Templates\t3e0ilfioi3684m2nt3ps2b6lru
    5 %AppData%\t3e0ilfioi3684m2nt3ps2b6lru
    6 %Temp%\t3e0ilfioi3684m2nt3ps2b6lru
    7 %UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe
    8 %UserProfile%\Templates\t3e0ilfioi3684m2nt3ps2b6lru

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1' = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1'HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1" %*'HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" - '"%1" %*'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"'HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.exe\DefaultIcon "(Default)" = '%1'HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CLASSES_ROOT\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\.exe\shell\runas\command "(Default)" = '"%1" %*'HKEY_CLASSES_ROOT\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\exefile "Content Type" = 'application/x-msdownload'HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[3 RANDOM LETTERS].exe" /START "%1" %*'HKEY_CLASSES_ROOT\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'HKEY_CLASSES_ROOT\exefile\shell\runas\command "IsolatedCommand" = '"%1" %*'

Related Posts

3 Comments

  • Alxamei Niji says:

    Thanks so much for this! It helped me to remove this scam from my computer.

  • Reki says:

    I download the free version of Malaware , I boot in "Command mode " DOS, and execute the EXE. It done the job ! 🙂

    Bye

  • kiera says:

    OMG THANK YOU SO MUCH!!! MY MOM WAS GOING TO KILL ME ONLY HAD COMPUTER FOR 3 MONTHS AND THOUGHT SOMETHING WAS ALREADY WRONG WITH IT! WHEW UR A LIFE SAVER

Loading...