Vista Internet Security

Vista Internet Security, sometimes appears as Vista Internet Security 2010 is a rogue computer security program that will display fake messages “Stealth program detected” and “Privacy threat.” Users can be easily deceived with this tactic and assume that these are part of Windows Vista. In fact, phony warnings are displayed intentionally by rogue security program to frighten victims. This scary tactics are ways and means of rogue programs to promote itself and convince user to obtain Vista Internet Security activation key or serial number. The malicious program is intended to be sold via fraudulent online activities as mentioned.

Do you know how fake antivirus infection took place? The most convincing approach to dig into user’s computer is by pretending as an automatic update coming from operating system maker Microsoft Corp. Users eagerly updating the system may not notice that the malicious program Vista Internet Security is being installed in the background. Once completed, virus scan will set without user’s involvement. The fake AV will hit Windows registry to give itself a spot on start-up items. It was found out that several versions of this rogue program namely XP Internet Security and Win 7 Internet Security are also targeting systems of the same OS version.

To remove Vista Internet Security 2010, use a combination of legit and trusted anti-malware and anti-virus programs only. Do not fall into a trap make you spend for worthless software such as Vista Internet Security.

Screen Shot Image:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Vista Internet Security Removal Procedures

Vista Internet Security REMOVAL TOOL:

1. Fix registry values modified by the malware.

- Click Start > Run and type command. Click OK or press Enter on keyboard to run DOS command prompt.

 

- From command.com window, type notepad. Notepad application will open.

 

- Copy the following text to notepad and saveas with the following attributes: File name fixexe.reg and Save as type: All files.

Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Classes\.exe] [-HKEY_CURRENT_USER\Software\Classes\secfile] [-HKEY_CLASSES_ROOT\secfile] [-HKEY_CLASSES_ROOT\.exe\shell\open\command] [HKEY_CLASSES_ROOT\.exe] @=”exefile”
“Content Type”=”application/x-msdownload”

- Close all running application. Locate the file fixexe.reg and double-click to start fixing registry.

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected computer.

MANUAL REMOVAL PROCEDURE:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “Vista Internet Security”. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
av.exe, ave.exe

2. You need to update your installed antivirus application to have the latest database.

3. Thoroughly scan the system and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to Vista Internet Security Virus.

4. Registry entries created by Vista Internet Security must also be remove from the Windows system. Please refer below for entries associated to the rogue program.
- For Windows 2000/XP: Go to Start > Run, type “regedit” on dialog box then press Enter on keyboard.
- For Windows Vista/7: Go to Start > Search Program and Files, type “regedit” and press Enter.

5. Exit registry editor.

6. Get rid of Vista Internet Security start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
av.exe, ave.exe

7. Click Apply and restart Windows.

Technical Details and Additional Information:

Malicious Files Added by Vista Internet Security
C:\ProgramData\BHklhsj81GT1
C:\Users\All Users\BHklhsj81GT1
%UserProfile%\AppData\Local\av.exe
%UserProfile%\AppData\Local\ave.exe
%UserProfile%\AppData\Local\BHklhsj81GT1
%UserProfile%\AppData\Local\WRblt8464P
%UserProfile%\AppData\Local\Temp\BHklhsj81GT1
%UserProfile%\AppData\Roaming\Microsoft\Windows\Templates\BHklhsj81GT1

File Location for Windows Versions:

  • %UserProfile% is C:\Users\<Current User> for Windows Vista/7, for Windows XP/2000 this is C:\Documents and Settings\<Current User>.

Vista Internet Security Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “av.exe”