Overall Risk Level: 
Internet Security 2010 is another counterfeit security tool for Windows and commonly promoted as an antivirus and protection software. Internet Security 2010 virus can get into the system by forcing itself to get installed utilizing a Trojan that will redirect Internet browser to a malicious security websites. When inside the computer, Internet Security 2010 and its Trojan will make sure that users will be having a hard time removing it and if possible all options to uninstall this program will be rendered useless. Internet Security 2010 will disable antivirus programs, Windows system functionalities and Safe Mode. Above all, Internet Security 2010 will alter system settings particularly the registry so that it will reign each time Windows is started.
A typical rogue software like Internet Security 2010 can be obtained by a malicious security websites, fake multimedia codec and by downloading an infected computer from an unknown source. If the downloaded program was installed, Internet Security 2010 will also be run on the background unknown to user. With this method, it will be hard for any security programs to detect that a malware is being executed. To be able to remove Internet Security 2010, we have included a procedure below.
Alias: -
Damage Level: High
Systems Affected: Windows
Screenshot Image of Internet Security 2010

Tags: Internet Security 2010 Trojan, Internet Security 2010 Virus, Remove Internet Security 2010
For Internet Security 2010 activation key, activation code, registration key, serial number and refund inquiries, please proceed here for the solution.
All contents, text and images related to "Internet Security 2010" are part of this website's information dissemination purposes. We don't endorse, sell or in any way connected to it.
93 Responses for "Internet Security 2010"
1. Download Malwarebytes’ Anti-Malware (mbam-setup.exe) and save it on your Desktop.
2. After downloading, double-click on the file to install the application.
3. Follow the prompts and install as “default” only
4. Before the installation completes, check on the following prompts:
- Update Malwarebytes’ Anti-Malware
- Launch Malwarebytes’ Anti-Malware
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.
6. Scan your computer thoroughly.
7. When scanning is finished click on the “Show Results”
8. Make sure that all detected threats are marked, click on Remove Selected.
9. Restart your computer.
Note: Internet Security 2010 virus may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.
Followed instructions, kills malware before it can update. Removes shortcut links on desktop so icon is useless.
Tried 10 times.
Even tried rkill.
Got Task Manager back but nothing else.
What process is it?
I can kill that
I got as far as Jim B and am hoping there is a process I can kill here. My computer is locked up on Task Manager but it is working so i could kill a process. If I have to shut down to get the computer working again I may not get rkill to work as it took many tries the first time around. I can’t get on Internet Explorer and I still can’t run Malware!!!
XP Auto logging off after account log in
This problem occurs after virus clean up Internet Security 2010 fake program
I had this same problem and it sounds like the common solution is to copy a new userinit.exe file to wsaupdater.exe. In my case, the registry key for userinit.exe was not pointing to wsaupdater.exe, it was pointing somewhere else entirely. The only way I was able to log in again was to edit the registry
In order to edit this, I downloaded and created a BartPE boot disk (http://www.nu2.nu/pebuilder/). After the file is downloaded installed it on a working computer running windows XP only .The downloaded file scan any XP only computer and build a bootable CD. After the boot CD is created, boot the affected machine from the bootable CD and follow these steps.
1. Click the icon in the lower left corner and select Run
2. Type Regedit
3. Highlight HKEY_USERS
4. Click the File menu and select Load Hive
5. Navigate to C:\Windows\System32\Config\Software (pick software and open)
Tip! if no sub folders is seen under windows make sure the file name field is blank or click in the
file name field and press enter you may repeat a few times until sub folders is seen
6. Name the hive something like MyHive
7. Open MyHive folder under HKEY_USERS
8. Navigate to KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
right click on (userinit ) choose modify next change the value of Userinit to
C:\WINDOWS\system32\userinit.exe
9. After you have made this change, it is important to unload the hive
10. Highlight the MyHive, click on the file menu, and select unload hive.
This should fix your log on problems.
How to manually delete Internet Security 2010
Internet Security 2010 manual removal:
Kill processes:
IS2010.exe 41.exe winlogon86.exe winupdate86.exe
HELP:
how to kill malicious processes
Delete registry values:
HKEY_CURRENT_USER\Software\IS2010
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Internet Security 2010″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “winupdate86.exe”
HELP:
how to remove registry entries
Unregister DLLs:
winhelper86.dll
HELP:
how to unregister malicious DLLs
Delete files:
IS2010.exe 41.exe winhelper86.dll winlogon86.exe winupdate86.exe Internet Security 2010.lnk
HELP:
how to remove harmful files
Delete directories:
C:\s
C:\Program Files\InternetSecurity2010\
XP Auto logging off problem Solved.
This problem occurs after virus clean up Internet Security 2010 fake program
I had this same problem and it sounds like the common solution is to copy a new userinit.exe file to wsaupdater.exe. In my case, the registry key for userinit.exe was not pointing to wsaupdater.exe, it was pointing somewhere else entirely. The only way I was able to log in again was to edit the registry and change key string to Under KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
to read ; C:\WINDOWS\system32\userinit.exe
In order to edit this, I downloaded and created a BartPE boot disk (http://www.nu2.nu/pebuilder/). After the file is downloaded installed it on a working computer running windows XP only .The downloaded file scan any XP only computer and build a bootable CD. After the boot CD is created, boot the affected machine from the bootable CD and follow these steps.
1. Click the icon in the lower left corner and select Run
2. Type Regedit
3. Highlight HKEY_USERS
4. Click the File menu and select Load Hive
5. Navigate to C:\Windows\System32\Config\Software (pick software and open)
Tip! if no sub folders is seen under windows make sure the file name field is blank or click in the
file name field and press enter you may repeat a few times until sub folders is seen
6. Name the hive something like MyHive
7. Open MyHive folder under HKEY_USERS
8. Navigate to KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
right click on (userinit ) choose modify next change the value of Userinit to
C:\WINDOWS\system32\userinit.exe
9. After you have made this change, it is important to unload the hive
10. Highlight the MyHive, click on the file menu, and select unload hive.
This should fix your log on problems.
This sounds like something too complex for me to do on my own. I have avoided registry messing like a plague because the guy who has now grown weary of helping, has told me all I will do if I go into Regedit is get into trouble. Anyone crazy enough to want to try to talk one through this should reply to my wife’s email, sanskee@sbcglobal.net, or call after noon at 281495-8541. Thanks if there are people willing to do this.
what if i cannot log into the internet in order to get the software?
Well, for me at least, Internet Security 2010 downloaded itself into the program files and ran itself as “IS2010.exe” or something like that. I killed the process from task manager and went straight to the .exe itself in Program Files, deleted it, and emptied my recycle bin. Seems to have worked for me…
Has anyone tried spyware doctor? i saw a post where people said it worked. But do not know if it was real.
Don’t miss understand a removal direction like my sister did, IS2010 took over malwarebytes and now I can’t do sh*t for her, I can’t even remove malwarebytes or get into anything else, I am even trying dos and that doesn’t seem to work. By the way the shut down problem is caused by it shutting down startup files. If you get logged in you can go into msconfig and select normal startup, hit apply and you should be good. Don’t pause or it will shut down again
the 12 steps didnt work, i cant even install, i also dont have any destop icons or the toolbar im an average pc use im not very knowledgeable with all these codes i jus want it off asap…
What legal action can we take against the makers of this malware?
I have dealt with a number of these variants, and got hit with this one myself (and I am a computer tech). I spent a fair bit of time this morning eliminating this. Primarily, I had to edit the registry and find the .dll files associated with this. It hides it’s components in a variety of locations, including under application data in the profiles. There are a number of instances of IS2010.exe on the pc, search for them and delete them all.
Also, rename the winhelper86, winlogon86 and winupdater86 files (if you can’t delete them) and this will help you progress. The directory created is:
c:\program files\Internet Security 2010. You must delete this directory. I also used MSconfig to stop the programs at startup.
This took me about 2 hours to completely eliminate. It also creates a protocal handler that stops you from accessing the internet. I used “lspfix.exe” to fix that part of the infection.
I can’t really give you “step by step” because depending on how infected your computer has become will depend on best practices for you. I honestly suggest having a knowledgeable computer tech help you out. Using regedit is not something to take lightly. YOu can scan the registry for all instances of IS2010.exe and safely delete those exact entries.
Always backup your registry before making changes
In regedit, go to file > export and save a copy of your registry.
Good luck….this one was not easy to get rid of. And ultimately, Malwarebytes m-bam.exe has been a terrific tool for many situations like this. If you can’t download it on the infected computer, use a flash drive and get it from another pc.
I hope some of this info helps someone….
Downloaded the free software, wiped out the 2010 virus in minutes. Thanks very much
I managed to kill the process by opening up a notepad document, write a few letters, then press the power off button at the computer. Everything but the notepad document shuts down, including the virus. It’s still stopping various programs and webpages though, so I’m running malwarebytes and manually searching for the files like Cindy suggested.
I’m not sure if using the notepad-shutdown technique works on all computers or operation systems (I have XP home edition), but it’s worth a try for anyone who is having problems deleting the infected files because they are currently in use by the IS program, and who don’t have access to the task manager (mine was blocked).
Oh, and when the option comes up to either save, not save or cancel the notepad document, press cancel. That will stop the shutdown process and leave you with an almost “free” computer. Pressing anything else will continue the process and shut it down, not much point in doing that.
I used Malwarebytes and it removed it quickly. I then searched and found instances of the IS2010.exe and removed them manually. I restarted and recovered my virus protection and then switched on the Firewall. After about 5 seconds my computer Blue Screened. I turned off and that was the last life I have had. My computer is dead… Maybe another problem which was an almost unbelievable coincidence as I have not had any prior problems.
My system seems worse than the rest. I cannot start anything, notepad, command prompt, tmanager, rkill, winzip, safe mode, etc. It also randomly open IE and goes to porno sites. Unless someone comes up with a new solution, it looks like reformat and reinstall XP.
hey cindy can u tell me what u did with lsp to fix your protocol thing? Ive removed IS2010, but my internet still isnt working completely
The very Very best thing you can do is back up all files you wish to keep in your system i.e photo’s, music, movies etc… and then run an intire system re-install. Yes it is a hasstle to re-install all of your programs i.e itunes, codex, windows office etc but you will always have apart of the “internet security 2010″ in your system. Because virus wise the risk is low, the damage the infection has, isnt worth trying to remove manually.
TAKE MY WORD. run the re-install. its healthier for your personal data in the long run
chur chur
IS2010 Removed!! I downloaded Malwarebytes Anti-Malware on another PC and burnt it on a CD. Installed it from the CD drive on the infected computer, did an update and ran a quick scan. It picked up all the infections and removed IS2010 completely.
It wipes out all anti malware programs, won’t allow me access to my computer or anythinAnyone? This thing is taking over fast.
I used a combination of several of these. First off, turn back on the task manager… for help use this link…
hxxp://www.pchell.com/support/taskmanagerdisabled.shtml
end task on IS2010.exe and check for smss32.exe I had both.
You can do a search for these files and delete them(or just use the malware-bytes). Then run malware-bytes on your computer and remove the files found. So far, it seems to be working for me.
@Cindy, been goin mad for days tryin to get my internet working after gettin rid of the is2010 virus, and that lspfix.exe did the trick! thankyou sooo much!!!!! :)
I got this and on my old laptop and now I can’t even turn it on. It just goes straight to a black screen. Do I just have to pay someone to fix it at that point?
I have the Internet Security 2010 virus on my pc. I cannot login to windows. I can’t even run safe mode. When I try to login its says “loading personal settings” and then immediately says “logging off…” If I put in the re-install disc in without being logged in to windows will I be able to run the disc? Any suggestions?
Downloaded rkill. Downloaded Malwarebytes from File Hippo (Trojans were redirecting links to malwarebtes.org and Cnet to go to virus products I’ve never heard of).
Couldn’t run rkill, so I installed and ran Anti-Malware as instructed. It removed all but 2 items whcih it said had to be done at reboot. Then I tried to run rkill again and it worked! My desktop went back to normal and Internet Security icons were removed from task bar.
Ran Anti-Malware again to be safe, but only found the same 2 items to remove on reboot. So I rebooted and everything looked normal. Then I ran a full scan with Anti-Malware. So far, just one item found.
Thanks so much for this info!!!
Forgot to add: I have McAfee antivirus and firewall. McAfee only found and asked me if I wanted to block registry edits which would have enabled Active Desktop. It was a file called e.exe in my Temp folder.
McAfee didn’t help at all with the rest. But I *was* able to turn on “Lock down firewall” in McAfee, which stopped all connections in and out. Perhaps this kept things from getting worse. I looked up your site on my phone, and turned off the Lockdown on my PC only to download the software.
Make or buy a boot disk that runs from your disk drive. I had this kind of virus last year around september. Got it off and now i have it again. I dont know how i got it this time. I was not downloading anytihng.
I have had an odd side effect… I removed it rather easily, When it happened I was on isohunt and the computer locked up and it gave me the Green Screen with the fake warning etc… I immediately opened up Malware Antytes and updated it to the newest version and it removed it. My odd side effect is now when I search it sometimes goes to random websites related to what I have searched for? Sometimes it goes to a random site? Very odd I have scanned it with norton/Malware Antibytes and it says it’s clean but I don’t know?
copy c/windows/system32/cmd.exe to desktop as cmd2.exe
double click on it
om your cmd line:
taskkill /IM IS2010.exe
taskkill /F / /IM SMSS.exe
then delete c:/program/IS2010.exe and c/window/system32/SMSS2.exe
then the pop up stop
run your malwarebytes
good luck
Wow what a hassle that was. Fortunately, VERY fortunately, I already had Spybot installed on my PC which I use about once a week. It ran a scan and identified all the malicious registry entries including the one which disables your task manager, took nearly an hour. Once I deleted all the entries I was able to pull up the task manager and kill the virus process. Found the IS2010.exe file and deleted it. Spybot just saved my butt. I have used it for about 8 years now and HIGHLY recommend you get this. It’s totally free but I think I’ll be making a donation to it. Called spybot search and destroy. Highly effective software.
Thank you for all the good information. Malwarebytes was the key to removal. After years of using Spybot it failed. My infection arrived via an email.
Now that this is contained Internet Explorer will not browse – only Google Chrome seems to be working. Any suggestions?
if you aint got the experience then just use Malwarebytes Anti-Malware… twice even 3 times, then run the TaskManagerFix that you will need from Google as your task manager will be locked to Adminsssss….. poxy little bugger of an infection.
well, I got the 2010 virus. It was very damaging. I ended up paying Norton $139.99 to remotely fix my computer. At that point I could not go on-line, I had numerous/continuous pop-ups from the virus and most of my programs would not function. The difficulty of knowing what to do was greater than my abilities. So far…it is working fine. I’m still not sure how “it” got in and I’m not sure how to prevent a re-infection. I certainly wish that the “guilty” inventors of this virus will be caught and severely punished.
Just do a system restore and it will be gone!
system restore does not work – I restore but it tells me nothing has changed – i have a hard time searching anything – it kills my internet browser – i can get on the internet but my screen freezes after awhile. I ran malware and it seemed to have gotten rid of it (at least some of it) . ran microsoft essentials and that found a ton of viruses. I recommend that. I tried one care but the virus seems to recognize this one and will not let me download it. I am going to have to pay someone to fix me I suppose. This is my first virus and Im not happy.
Okay I got this this morning right before going to sleep (I stay up all night and go to sleep in the morning) so I haven’t gotten any sleep in a really long time thanks to this.
anyway, I downloaded malwarebytes and the first time I tried it it didn’t find anything, which was weird. I couldn’t do anything like run task manager, go to certain sites, run certain programs, and i couldn’t delete the internet security 2010 file. So I ran the computer in safe mode and for some reason I was able to delete the program that way. So now the program is gone but i’m still having problems. I can’t run task manager, everything is pretty slow, and the computer is still telling me I have problems. The background is still the “INFECTED” thing. Oh and I can’t do the registry thing that everyone is talking about because it won’t let me run that (Just like with task manager)
I was able to get all my important files off so I’m not too worried about that. I wouldn’t mind doing a system restore, in fact i’d LOVE to. But I can’t. I have a mini and that means it didn’t come with the windows xp CD. I know there is a way that I can put it on a usb drive BUT I don’t even have a disc for that so that’s not going to work unless I can get one.
Oh , I’m also able to go to any site right now. I can basically use my computer it’s just really slow and I’m unable to use task manager and other things.
So, uh, can ANYONE help me out? I’ve been looking online for anything to help and everything does not seem to be working out for me. please email me at bedazzledcobraveins@gmail.com if you can help.
I seem to have everything deleted and restored, but my boot up seems to be taking much longer than normal. Has anyone else experienced this problem? Any suggestions about how to correct this?
If you can get into Safe Mode, run Malwarebytes from there – there are fewer places for the Trojan to hide!
Restart and run it again to make sure…
It’s worth noting that the big green warning message ‘Your System is Infected!’ is not a real popup – it’s just a pic that replaces your wallpaper. Go to display settings to get your old one back.
[...] 2010 virus I hate that this is my first post to this sub-forum, but here it goes: I had the Internet Security 2010 Virus (link is to info on the virus) which was a pain in the butt; but from my understanding, not [...]
ok guys those who couldnt run rkill.exe, here is the trick. after you start rkill if you get a message that rkill couldnt be started, just ignore that message, dont do anything on that message window, leave it like that, and start rkill again by double clicking rkill.exe and this time it will stop all the processes related to the spyware, it kill kick all those bustards out. then run malwarebyte and do just a quick scan. delete everything found, restart the pc and do a full scan and remove if anything more is found and restart again. keep the internet off all the time, and hook up again after the full scan is done.
i cant even dp this when i try and run the rkill the virus pops up and i dont even see this message window that says it cant be started, any suggestions?
Thanks for everyones posts. could not get rkill to work or task manager. got task manager working this did not help me as it kept coming back…. Malwarebytes would not run… kept freezing on one file. Booted in safemode ran malware and it worked!!! rebooted PC and evrything seems fine now.
I seem to have removed the virus–or some of it–but now only my antivirus programs cannot access the internet to update. I can get on the internet using a browser.–I already checked windows firewall–there is nothing that should be blocking these programs–I just want to update all my virus programs to make sure its completely gone.–keep getting message unable to connect to server or similar message depending on program.
I used SpyBot in Safe Mode when logged in as administrator – I too suffered the same issues as others with both Task Manager and Regedit being disabled. However, after running Spybot (make sure you install the latest updates – and Spybot’s free to use) I rebooted the PC, then ran it again and the various pop-ups are now gone. However, when I go to access Display I can’t change the background and access any of the listed files. Any suggestions?
I got the 2010 virus yesterday, and by today I can’t even log into windows. I’ve read other peoples posts with this same problem but haven’t had any luck finding a solution. I’ve tried safe mode and the same problem occurs. I am logged off before even being logged on. Please help
I used Malware bytes and rkill to remove this virus, however, now I cannot get on the internet. (I’m on my work computer to post this). It just says page cannot be displayed. Email will not load either. Any idea how to fix this? All the settings are good, I reset the modem and router. Wireless works fine on my laptop.
To linkupsuper
Can you please advise if your solution allows access to data again or does it cause all the data to be lost.
I want to try it but if i cant recover my data i will format instead.
I ran malware bytes, removed everything and all seems fine now except I cannot load any webpage. Nothing even happens, no errors just nothing happens. Anyone else had this and managed to fix it? Cheers.
Ran into this a few times and it’s not worth cleaning (if you can at all). If the virus is dug in enough, you’ll never get it out.
Data? Yes, not hard at all. Easiest way is to use a linux live cd – ubuntu is great. Download the ISO from their website, burn it to cd or dvd and boot to it. When you get to the main screen you’re given options to either install or run without making changes – run it without making changes (DO NOT RUN THE INSTALLER) and the linux desktop will pop up in a few minutes.
Linux will load without damaging your current system and you’re going to find out in a hurry how secure microsoft really is (it’s a joke) cause you’ll be able to access everything on your current hard drive without passwords.
plug in a usb drive or whatever you have and copy your data. You can surf the web, transfer all your data – everything you need to do before formatting.
Good luck.
after 5 days i think i removed some of the major components of the virus. What I still have in the startup files is ssms 32 and whenever i cut it off it says only the administrator can do this and i am the admin. the other problem is i cant get to the internet. It is blocking that can somone please help me with geting my admin feature back so it will allow me to cut it off in startup and how do i get my internet back.
Hey,
So Spybot pretty much fixed my system from this virus, with one excpetion: the virus puts an ‘infected computer’ image as the wallpaper, then locks the wallpaper selector. Anyone know how to unlock the wallpaper ??
I got this virus tonight..
Does anyone know where it came from? Can it be launched from an MP3 or FLAC file? That is about the only thing I downloaded on the system today. Actually, 1 FLAC File.
Anyways, there is another web page out there with instructions for rkill and malware program.
Like someone above said, run RKILL and when it warns you it can’t run, just run it again and wait, it should kill the processes. Then you should get back taskmanager and can run malaware program which should remove it.
You might want to try safe mode also (f8) when rebooting.
I’ve got the same problem others have though – It’s killed some network sub system.. I can’ browse or FTP or do anything on internet.
I am going to try LSPFIX.EXE like someone reccomended.
hxxp://www.cexx.org/lspfix.htm
I’m not with the computer now so have to wait until tmr. Seems like it might work, that malware hosed something needed to browse.
This sucked! I spent about 4 hours on it, since I couldn’t browse I thought I still had it. And after it was removed it was still there… I also cleaned out RUN folder in reg, used MSCONFIG to kill some startup junk and used HIJACKTHIS to kill a few things.
Well I got Internet Security 2010 trojan then used spybot search & destroy to find all names of to do with this program malicious bug. I removed it with malwarebytes and avast, but now my computer loads fine, but there is absolutely nothing on my desktop for icons etc. to scan again etc. Now it brings up a box that says Spyware Alert! Worm.Win32.Netsky detected. At this point not sure what to do since I can’t find a programmer to help me out with this. Does Anyone have a suggestion please
I followed linkedupsuper advice with pebuilder; still can’t log on. when i go back and look at registry after trying to log on, it has changed back to X:\i386\system32\userinit.exe,
I worked on my problem some more this morning. The malware was still there. I ran spyboy search and destroy and dr. web. Dr. web found it but I couldn’t delete anything. I deleted the files manually or renamed them. spyboy found some other stuff and removed it.
lspfix didn’t fix my internet issues.
This MS Fix did though:
http://support.microsoft.com/kb/811259
There is a ‘fix-it’ link that restored my winsock and now internet works again.
It seems like the system is slower, wondering if my disc caching was turned off or something else done to affect system performance.
i have gotten this puppy from weather.yahoo.com !!!
anyway, removed HD and hooked up onto another PC and killed the sucker there with dr web cure it and by deleting folder program files/internetsecurity2010
death penalty for those stupid crackers !!!
I’m infected by IS20100, a very stubborn infection to get rid of. Can’t run task manager, cmd, surf the internet, safe mode boot, etc. The folder in c:\program files\internetsecurity2010 folder is empty. Deleted it but no effect. MSconfig doesn’t work as well. The pesky hides itself somewhere else and every few seconds it pops up warning sign which makes difficult to work on. The only thing I could do was to backup my files and scan it on another PC and I am going to blow my PC away and reinstall. yep! Death to the damned crackers!
I ran spybot search and destroy as soon as i saw the window popping up that i had 25 trojans. Also there is a typo in the wallpaper that 2010 puts on the computer.I use my laptop for internet browsing and random things, I don’t download files to it. I couldn’t delete the program file, open my registry, or anything else to manually delete it. After spybot found registry changes and did its thing, i did a system restore and that fixed everything (so it seems). i’ve been looking for the files and registry keys and haven’t found anything.
I was using my computer and the internet security window popped up…is that the beginning of the virus? I immediately tried to run an update to my virus scan, unplugged the internet and scanned for viruses. There weren’t any, HA so I took it to a tech and he cleaned the virus but the “operating system” doesn’t work. That’s okay I can have that fixed, I am concerned about my documents and credit card #’s etc.
Does anyone know what this virus does, did it rob me of my personal info and IP address…things I have been reading about…Im very concerned.
okay I am such a novice I couldn’t get my first message to post. I was using my computer when the internet security 2010 windows started popping up. I closed all the windows and restarted my computer. when they came back i tried to update my virus scan and then unplugged my internet connection and ran the scan. No viruses HA. I didn’t plug it back in, i took it to a tech and he removed the virus but told me my “operating system” didn’t work and he needed my original discs. I haven’t decided whether or not to fix it.
My main concern is what does this virus do? Were the windows the beginning of the virus? I am concerned about my documents and personal info that may have been in the computer. I paid my insurance by credit card an hour or so before the windows popped up. Was I being robbed of that info, or is the purpose of the virus to destroy my computer?
Thanks, you all seem to know so much and I am really concerned!!!
I just fixed a friends PC that had this nasty! Used MalwareBytes, combofix, Spybot and that got it. I would guess it took about 3 hours. This one is really on a rampage as we can see by all the posts!
I have the same problem as Shannon. What can I do? and wife is on my case. Any ideas?
same here as Steve and Shannon. Can’t even logon. Safe mode didnt work.
thanks!
I have been trying to get rid of this sucker for 5 days now. I have tried everything. Combofix has a bug in it so it started deleting my files on top of the mess from the virus. There is a fix posted for that but still having problems.
Yesterday I finally resorted to doing HP recovery. There was another program I used besides for rkill check out this link bleepingcomputer.com/virus-removal/remove-total-security and go to process explorer download link. That finally allowed me to start task manager and get into registry. Rkill.exe only worked the 1st time. Don’t forget when doing this to shut off system restore.
So after I did my HP recovery I ran malwarebytes just to be safe. It found infection. Kept running until no infections were found. Then I ran AVG and it found infections and got rid of them. Now I am trying to run in safe mode to be sure it is all gone and my computer keeps shutting down at a certain point of running through malwarebytes scan.
Please help. I see everyone is frustrated. Has anyone run into this problem when thinking they finally got rid of it? I can go on the internet now and run things normally but I know it is still there.
I have the internet security virus 2010. i am now unable to restart my computer. it just keeps trying to restart over and over. i cannot even put it in safemode. Please help
I don’t know about computers. I was infected by IS2010 last night. The virus WOULDN’T ALLOW me to perform a “System Restore”. Thanks to this response forum, I downloaded Spybot and it fixed 90 problems. The virus was STILL THERE. The difference was that after running Spybot I was finally able to gain access to “System Restore”. I changed the date and my computer automatically rebooted. I thought it was too good to be true. It seems like everyone’s computer has a unique problem from the virus than the next person’s. I recommend anyone try what I did. I am so glad that I was able to find this response forum again so that I could share my easy(and maybe lucky) solution. Reminder: I am a computer dumb.
If you are not able to access “System Restore”, run Spybot. Spybot will fix like 90 problems, but the virus will still be there. THEN try “System Restore”. I was able to access “System Restore” AFTER Spybot finished. It worked for me.
This virus is the absolute Pitts!
I’ve tried to wipe it off my pc for 4 days and failed. I eventually could not log on, could not restore, could not do a winxp repair. nothing.
Ended up doing a clean install tonight and once xp fired back up I immeadiately fired up my firewall and installed anti-virus. 15 minutes later I got a warning that I still had it…after a completely new install!!!!!!!!!
WTF!
I have a friend’s computer that has the Internet Security 2010 on it. He didn’t know what was wrong. So I was on it for about 15 minutes just to find out what was going on. Then that blue screen came on. I restarted and tried 4 or 5 times and I couldn’t even use Safe Mode because the blue screen has come back. Honestly, I only know a little about computers but had a similar problem that’s why I thought I was able to help. This is what the screen showed:
A problem has been detected and Windows has been shut down to prevent damage to your computer.
PAGE_FAULT_IN_NONPAGED_AREA
If this is the first time you’ve seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:
Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware of software manufacturer for any Windows updates you might need.
If problems continue, disable or remove any newly installed hardware or software. Disable Bios Memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode.
Technical information:
*** STOP: 0×00000050 (0xc9464369, 0×00000000, 0x 8968208c, 0×00000000)
Please help. I’ve noticed a couple of people here with the same type of problem that could use help as well. Thanks so much!
I’m curious as to who is behind the malware installation. It was installed on my computer when it came home from Software Emporium inc. I’m curious. if it is such an infamous malware, why are experts having it installed on my computer?
Success story here. 2010 Internet Security virus invaded my older laptop two days ago. I was barely able to get into safe-mode and was unable to run System Restore at all. Other functions like desktop and display were compromised.
I downoaded Malwarebytes’ Anti-Malware free version software and copied it to CD. After running it on my infected laptop, and finding 43 infected items, all traces were removed.
Thanks for the advice here and never give up. I almost did!
Me again. LOL. I keep trying using F8 and Last Known Good Configuration. Probably took 50 times to finally to get this complete. So I was able to run the Malwarebytes using a CD. I did the full scan with it but the Blue Screen would seem to pop up at any time, so I decided to run the quick scan. Which was able to complete and there were about 232 infections. I restarted the computer like it recommended. I figured that did the job, so to make sure I would still run the full scan. After about 17 minutes, the Blue Screen came back up. I waited then restarted and the Blue Screen came up again. I’m not sure what to do know since I was able to run the Malwarebytes. Can anyone help?? Thanks!
Whoever put out this piece of s— should be hung by the short hairs. This thing has cost me more time in tryig to remove it then all other viruses put together. None of the solutions worked on any system I have. IT took over my whole system and all processes and none of the files expressed in any documentation exists on my system. I’ve deletedall the files that are associated with IS2010 and after a reboot all comes right back. I know there’s a DLL file where it reinstalls from but I haven’t found it.
My next step is to reinstall all windows and hope I don’t lose anything I can’t get back and yes, I have backups of all programs but since its not my system I don’t have backups of the specialized software.
If I find something, I’ll be sure to post it.
Hi
Got hit with this virus yesterday on home pc and I see from the posts above that I have the same problem as quite a few others whereas, I can’t log on as it logs me straight back and I can’t even access safe mode. Has anyone found a solution for this yet? Would appreciate any help
Cleaned this nasty off a friends PC about 10 days ago. He called today and said the 2010 pop ups were back. Had him run Malware again and restart. Pop ups are gone but I think we still have an issue because he cannot update malware, spybot or mcafee. Any suggestions to do a deeper clean?
Thanks,
Brian in MI
Woah! It looks like I’m not the only one trying to kill this annoying virus.
I got the virus a few days ago and used RKill and Malwarebytes and restarted the computer.
The pop-ups still remains despite removing the registy keys with Malwarebytes. Can’t seem to find the files of it either T-T
Try combofix. It is freeware, but donations are accepted. You need to be VERY patient and let the program do it’s thing. It may take a while to run. Good Luck!
I’ve been hit with this virus as well, but the only errant file that is running when the virus pops up is av.exe. As soon as I end this process the pop-ups stop, but as soon as I run malwarebytes, it immediately starts up av.exe and doesn’t open malwarebytes anti-malware. I was able to download and run SUPERAntiSpyware though, and am currently waiting for it to finish. Hopefully, if it doesn’t quite get everything, it’ll get enough for me to be able to run malwarebytes.
When this first hit me, I saw the unusual popup, then about 10 seconds later my computer rebooted, and coninued to reboot before it would even load windows. I had to boot from my OS CD and re-install the os before I could actually do anything about this on my computer. Thankfully, I didn’t lose any files or programs during the re-install.
You have to run rkill.exe first, which will kill any malware that’s running. Then you need to download malwarebytes software, but you’ll need to download a key executable seperately because the Internet Security disables part of the malware program. Then you’ll be able to remove it. Here are the instructions – they have worked for me twice: bleepingcomputer.com/virus-removal/remove-internet-security-2010
One more thing, the second time I had this infection, the rkill.exe I had downloaded originally would not work – it kept getting killed by the malware. I downloaded new copies and burned them on a disk then ran the rkill from the disk. This worked.
Good luck.
Malwarebytes will not kill this virus in my case. I have ran and it appeared fixed, removing all the infected files but later the dang thing came roaring back with a vengence. I have sucessfully update m bytes and ran several times.
I had to download a renamed version of malwarebytes exe file in order to run it, cause this virus deleted the exe file if you try to download it. the new exe is randomly named, like O9h2tt98.exe and ou put in programs/malwarebytes and run it.
anyway, still no luck, i will try searching regedit for is2010.exe but what if they also have versions renamed randomly like mbytes ?
I caught this virus yesterday, it was the first time i came across this internet security 2010. I thought there was an older version that came up and i could just hit X and close the program out. Well this program ran halfway before i knew what was goin on. I got it shut down and ran windows defender and it found the virus and it deleted it but i didn’t let the scan finish. I think there is parts left on my computer. I cannot open my virus program, i cannot download any programs. If i try to open something it asks me what i want to open it with. Luckily i can still get on the internet. I can go into safe mode also. Ive been searching all day on ways to get rid of this piece of crap. I cannot find the rest of the files. Any advice will be appreciated.
I can do a restore but it only restores to yesterday when i caught the virus.
I have this nasty virus on my pc at work. nightmare. Help……..
i have deleted is2010 from taskbar, an cannot do a sucsessfu system restore
I have the same problem as (dns6181) I can not open any the except internet explorer. It has block task manager,control panel, and when I try to download any file that can remove this program it say I have to run it some where else if you can please help. Email me at burns.olivia@yahoo.com
I got infected with this terrible virus, but it wasn’t called IS2010.exe on my computer, could not find any reference to that name at all. It was identified as “av.exe” in the task manager, I stopped the process & did a search, found the only av.exe file in the Prefetch folder, so I deleted that. Now it seems I have my computer back, no other instance of IS2010 are running. I can run my malware (couldn’t before) so we’ll see whether there is a deeper infection. I’ll post my progress.
I’ve now managed to get this virus twice in less than a month and I only stick to good old trusted sites and no downloads!!
First time I just handed it in and had to pay £150 so not doing that again. It has had different names both time (this time something with XP in it), first time it crashed the laptop completely now at least I can end the process (av.exe) for a few minutes at a time and it doesn’t shut down the laptop.
I’ve always used the free version of AVG and never had any problems before but I guess I have to get a better anti virus program now…
Anyway, I don’t know much about computers from a user point of view (ironically I’m working in IT) but my next plan of action is to reinstall XP. I noticed someone mentioned this in an earlier post…could anyone give me some info on this..could it work?
as soon as the pop ups started commin up, i knew something was wrong, thank god i looked it up on the web and surley it was a virus, all i did is system restore it back 3, 5 dys and it worked like a charm… also thnx to firefox i could access the internet, on the windows internet browser it wouldnt let me, poping some msg that its not safe and might b infected….go firefox, good luck guys…
Take the computer out of the infected system. Add as a slave drive to another system. Scan it with Avast Free antivirus and Malwarebytes. Your system should be good to go. Has always worked for me.
I fixed it in one (alabeit 7 hour long) sitting. It came down to using rkill and doing a mbam quick scan and letting it scan. I caught it in its beginning stages, thank god.
I ran rkill and Malwarebytes, rebooted, scanned, rebooted and all the popups stopped. :)
I have another problem now – the Run As command keeps popping up every time I open programs, even when firefox opens a new window. Is it related to rkill or malwarebytes?
Any Response?