Win 7 Internet Security 2011
Uninstalling the rogue program ‘Win 7 Internet Security 2011’ requires an effective anti-malware tool. You can find a quick removal guide on this page and a useful tool to instantly delete this malware.
Win 7 Internet Security 2011 is believed to be a member of the rogue anti-virus program family. It is observed that is Trojan utilized to spread the software to computers connected to Internet. Win 7 Internet Security 2011 virus may enter the computer freely by spotting security weaknesses. It can install itself without the need for user’s interaction. After acquiring a place on the system, Win 7 Internet Security 2011 causes several annoyances including frequent display of forged warning messages attempting to make users believe of transpiring infections on computer. Fake virus scan conceive by the same product also claims that system files were infected and propose for instant removal.
Before any of the classified threats can be taken out from the system, Win 7 Internet Security 2011 notifies users to obtain the registered version first. This is carried out in the form of pop-ups and task bar alerts. Additionally, Internet browsers is redirected to an online payment processing web site that force users to give out credit card data to purchase full version of this rogue tool.
Remove Win 7 Internet Security 2011 and other computer threats and virus only with a legitimate application. Having a paid version of useless program will not help resolve computer issues.
Screens Image of Win 7 Internet Security 2011:

Technical Details and Additional Information:
Damage Level: Medium
Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7
How to Remove Win 7 Internet Security 2011
Step 1 : Activating Win 7 Internet Security 2011
The malware will block running of any programs. It also prevents access to Internet particularly anti-virus web sites. Execution of Windows tools like Task Manager, Registry Editor and Control Panel is similarly block by the rogue program. Activating the program using the registration key below will regain access to the mentioned services.
Once activated, downloading of necessary program to scan and remove Win 7 Internet Security 2011 is now possible. Use the registration code below. If it prompts for email address, you can input any email address.
REGISTRATION CODE: 1147-175591-6550Step 2 : Scan the computer with recommended removal tool
1. First thing you should do is reboot the computer in Safe Mode with Networking to avoid Win 7 Internet Security 2011 from loading at start-up.
NOTE: You will need to PRINT or BOOKMARK this procedure, as we have to restart the computer during the removal process.
To start Windows in Safe Mode with Networking, please do the following:
a. Remove all media such as floppy drive, cd, dvd, and USB devices. Then, restart the computer.
b. Before Windows begins to load, press F8 on your keyboard.
c. It will display the Advanced Boot Options menu. Select Safe Mode with Networking.
d. Windows will now start in Safe Mode and at the same time will load necessary drivers so that you can access the Internet.

2. Download the Removal Tool and save it on your Desktop or any location on your PC.
3. When finished downloading, locate and double-click on the file to install the application. Windows' User Account Control will prompt at this point, please click Yes to continue installing the program.
4. Follow the prompts and install with default configuration.
5. Before the installation completes, check prompts that software will run and update on itself.
6. Click Finish. Program will run automatically and you will be prompted to update the program before doing a scan. Please download needed update.
7. When finished updating, the tool will run. Select Perform full scan on main screen to check your computer thoroughly.
8. Scanning may take a while. When done, click on Show Results.
9. Make sure that all detected threats are checked, click on Remove Selected. This will delete all files and registry entries that belongs to Win 7 Internet Security 2011.
10. Finally, restart your computer.
Note: If Win 7 Internet Security 2011 prevents mbam-setup.exe from downloading. Download the software from another computer. Renaming it to something like 'anything.exe' can help elude the malware.
Step 3 : Ensure that no more files of Win 7 Internet Security 2011 are left inside the computer
1. Click on the button below to download Norton Power Eraser from official web site. Save it to your desktop or any location of your choice.
4. Once the file is downloaded, navigate its location and double-click on the icon (NPE.exe) to launch the program.
5. Norton Power Eraser will run. If it prompts for End User License Agreement, please click on Accept.
6. On NPE main window, click on Advanced. We will attempt to remove Win 7 Internet Security 2011 components without restarting the computer.

9. On next window, select System Scan and click on Scan now to perform standard scan on your computer.

10. NPE will proceed with the scan. It will search for Trojans, viruses, and malware like Win 7 Internet Security 2011. This may take some time, depending on the number of files currently stored on the computer.
11. When scan is complete. All detected risks are listed. Remove them and restart Windows if necessary.
Step 4 : Remove the Rootkit Trojan that installs Win 7 Internet Security 2011
Rootkit Remover is a stand-alone utility developed by McAfee. It can be used to detect and remove rootkit Trojan that is associated with Win 7 Internet Security 2011. This tool can detect rootkit that is part of ZeroAccess and TDSS family.
1. Download Rootkit Remover and save it to your desktop or any accessible location. Click the button below to begin download the tool.
2. Locate the file rootkitremover.exe and double-click to run the program.
3. When User Account Control prompts if you want to allow the program to make changes on the computer, please click Yes.

4. Rootkit Remover instantly scans the computer and look for presence of Trojans, viruses, and rootkit that is related to Win 7 Internet Security 2011 .
5. Once it finishes scanning the computer, the tool will require you to restart Windows.
Alternative Removal Procedures for Win 7 Internet Security 2011
Option 1 : Use Windows System Restore to return Windows to previous state
During an infection, Win 7 Internet Security 2011 drops various files and registry entries. The threat intentionally hides system files by setting options in the registry. With these rigid changes, the best solution is to return Windows to previous working state is through System Restore.
To verify if System Restore is active on your computer, you can type system restore into the Start menu search box. Typing rstrui on the same box and pressing Enter also opens this function.

If previous restore point is saved, you may proceed with Windows System Restore. Click here to see the full procedure.
Option 2 : Win 7 Internet Security 2011 manual uninstall guide
IMPORTANT! Manual removal of Win 7 Internet Security 2011 requires technical skills. Deleting system files and registry entries by mistake may result to total disability of Windows system. We advise you to perform a backup of registry before proceeding with this guide.
1. Kill any running process that belongs to Win 7 Internet Security 2011.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for Win 7 Internet Security 2011 files (refer to Technical Reference) and click End Process.

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit and press Enter. This will open registry editor.
- Find and delete registry entries as mentioned in Technical Reference section.
- Close registry editor. Changes made will be saved automatically.

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.
- Thoroughly scan the computer with your updated antivirus software.
4. Delete all files dropped by Win 7 Internet Security 2011.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Technical Reference'. Make sure that you execute 'End Task' first before deleting the file. Otherwise, the system will not let you perform this action.
Technical Reference
Associated Files and Folders:File Location for Windows Versions:Added Registry Entries:
- %UserProfile% for Vista/7 user is C:\Users\<Current User> for Windows Vista/7, for Windows XP/2000 this is C:\Documents and Settings\<Current User>.
Troubleshooting Guides
Did Win 7 Internet Security 2011 blocks your Internet access?
It is usual that rogue program prevents user from downloading removal tools from the Internet. Thus, infected computer may be denied to access the Internet by making changes to computer's proxy, DNS, and Hosts file. To fix Internet connection problem, follow these steps:
1. Download the free program called MiniToolBox. Click the button below to begin. Save the file on your hard drive or preferably in your Desktop.
2. Close all running Internet browser and double-click on the file to run. It opens a window showing a list of features.
3. Make sure that you have a check mark on the following items : Flush DNS, Reset IE Proxy Settings, and Reset FF Proxy Settings.

4. Click on the GO button to start the process. The program automatically closes and displays a text file for your reference.
5. If the above solution does not work, you may try other method like fixing a virus-blocked Internet access. Also, make sure that your hosts file is free from any malicious entries. View steps in cleaning Windows host file.
Lilian
Dec 31, 2010 @ 22:40:20
good info
Jim
Mar 31, 2011 @ 11:07:21
Just cleaning this off of a machine tonight. It also remove or renamed msconfig, regedit, taskmgr and eventually removed the file association for .exe files.
In the end I needed to perform a system restore to a week ago, just so I could get msconfig running to block all startup programs and services. Only then could I get malwarebytes installed and eventually cleaned everything out.
mellyanya
Mar 31, 2011 @ 20:16:29
Thank you very much!
martyn
Apr 01, 2011 @ 11:14:02
I simply used system restore after hours of trying other things and it worked!!
Anne
Apr 02, 2011 @ 17:02:11
Going to try this on my mom’s computer. This virus also eithere trashed or blocked access to her restore points, so that doesn’t seem to be an option for us at this time. Many fingers crossed that it will work!!!!
MDRV
Apr 05, 2011 @ 21:20:32
Hi i found a solution not the best but it works i searched the process in tskm and changed the file ending from exe to txt so this program was unable to start i actually didnt found this prog actually any where on my pc but it seems to be completly disabled
Keris
Apr 30, 2011 @ 03:11:41
I’m on here on my iPhone cause my computer it’s blocking me from visiting the site! Thanks
lisa
Apr 30, 2011 @ 03:38:40
what program did you find in task manager that you changed from exe to txt to stop it from running? I can’t logon to any internet site to run any fixing program.
shayla
May 01, 2011 @ 01:55:23
The Win 7 Security 2011 has blocked my internet . So i cannot do anything to remove it . Help please ?
Lisa
May 02, 2011 @ 16:32:20
Hi, this virus has also blocked me access to internet. How do we get rid of this. Step by step instructions please as I am not that computer savy. thanks.
Lisa
May 02, 2011 @ 16:34:09
I contacted Win 7 Internet Security 2011 about this and this was their response…
I am really sorry that your computer has been infected. So, these pop-ups and are not the part of our product,
they are a some kind of a virus from the internet and don’t belong to our program. It was done by our advertising
partner and he’s already banned.
This program will be self-removed in 6 days. There would be no problems after it is deleted.
Also you can just set date and time setting in your windows control panel 6 days later according to current date.
Is this true… will setting the date ahead by 6 days remove this virus?
steve macke
May 02, 2011 @ 21:12:56
I removed it with avast – downside was I also removed the exec files that it infected – so I had to do a repair in safe mode after saving all the files – it took two hours to go through the repair wizard – then another two hours updating the windows 7 os and downloading avast and other security software so that does not happen again.
Did send a message to the scum bags that created the virus – they did not keep me down
Michelle
May 03, 2011 @ 21:00:21
I was infected with this virus just last night. After trying several things to get rid of it and after numerous times trying to get on the internet only to have it blocked by this virus, I clicked on “online support” on the menu bar of Internet Explorer. When I clicked on this option, the Microsoft webpage opened up and I was able to go to the forums and find out about fixes for this virus. Then I discovered that I was able to go online from the Microsoft website and onto the internet to confirm fixes. I ended up downloading the Malwarebyte shareware and got rid of this annoying virus. Where there’s a will, there’s a way! :-)
mike s
May 07, 2011 @ 22:01:02
i tried to get rid of this virus many times using superantispyware and it didn’t work now every time i try to access the internet and open with pops up can you help me out with something elese i tried also using safe mode by pressing f8 and nothing evry help is appreciated thank you reply a.s.a.p
mike s
May 07, 2011 @ 22:02:18
i was infected yesterday just today got access to another computer any advice is grateful
mike s
May 07, 2011 @ 22:05:20
now my comp. just turned off and wont turn on what has happened help me please !!!!!!
i will help you
May 08, 2011 @ 04:37:26
Press CTRL+ALT+DEL & Select START TASK MANAGER . THEN SELECT PROCESSES & HIGHLIGHT ON yto.exe . AFTER THAT SELECT END PROCESS.
Dave
May 13, 2011 @ 08:50:25
I used MBAM to remote an infection of Windows Internet Security 2011 from a Windows 7 (enterprise) 64 bit system. Although alerts, reg keys and files seems to have been removed, I can now no longer run many programs as the infected user (click Run As Administrator works)
Re-running MBAM to see if it finds anything else. Otherewise this system is screwed and i will probably have to reimage it.
bill
May 14, 2011 @ 17:15:54
infected by win 7. struggled for hours. local office depot offered to remove for $180. to avira knowledge database. to support for home. to line 7 “i have a virus…”. to see also. to how can i get an avira rescue cd. i downloaded and burned cd. installed cd in infected computer. instant success!
carlos
May 16, 2011 @ 21:03:48
This happens to me quite often when I visit dodgy sites. Ahem.
McAffee useless at stopping it.
I turn off computer,
turn on again pressing F8 repeatedly,
choose ‘Repair your computer’(1st option at top)
then choose local user (my name) with no password to get to next menu
then choose ‘System restore’
and choose a recent date from the list when it didn’t have the virus. Everything works ok after that.
If the trojan’s still there it doesn’t pop up any more.
And so, back to the porn.
Peggy
May 16, 2011 @ 21:54:12
It is a bad virus that does not allow internet access. Also if you buy the software, it does not work but my Credit card company told me that it was being charged to some place in Iraq!!!!! I put a fraud alert on and had my card discontinued!!
Sean
May 17, 2011 @ 22:39:27
Thanks Carlos – your solution is the only one that worked quickly – I couldn’t access system restore without using the repair option in safe mode.
Dwight
May 19, 2011 @ 17:28:11
hi friends,
I fixed this problem as follows:
a) Restart Computer
b) Press F8
c) Repair Computer
d) System Restore to earlier check point
e) Start Windows
f) Launch Google Chrome
g) Download Malware Bytes
f) Run scan.
If you want to do manual process:
a) Restart computer
b) Press F8
c) Safe Mode with Command Prompt
The files you need to delete will be in a folder like this:
c:\users\user\AppData\Local\Temp\
C:\users\user\AppData\LocalLow\Sun\Java\deployment\cache\6.0
c:\users\user\AppData\Roaming\bitrix security\
you can try
a) del *.*
b) rmdir [directory name]
I was not successful from the command line because I couldn’t find where the programs were hiring until I used the scan tool.
Good Luck………
stuie
May 23, 2011 @ 12:23:09
does using the system restore method delete everything else off the system??any answers would be great cheers
DJ
May 24, 2011 @ 05:35:06
Just got infected with Win 7 Security 2011. It didn’t let me access the internet to get rid of it so my solution was to go on a clean computer, download Malwarebytes Anti-Malware to a CD, put the CD into my infected cpu and run the program as the administrator, it was removed within 5 minutes.
tembo
May 25, 2011 @ 16:23:31
-The only browser that will work if you have this is I.E.
-Do not try to log in to anything.
-Un-plug your internet connection.
Here are a few of tricks:
The file name is unique based on your computer, and usually takes the name of another program.
Find the name via taskmanager, ctrl-alt-del.
Now name a random exe file on your computer the same name then place that file in the appdata\local folder of your user account name.
When the window pops up right click it on the taskbar and go to properties. Proceed to edit the settings, change the file extention, etc change the right, etc. This will render it useless.
Malewarebyes is a good way to get rid of it, Norton free is also.
Norton won’t get rid of it via a scan, but rathere through it’s sonar technology. This examines suspicious behaving programs. After a bout 30-minutes to an hour Norton will detect that it’s malicious and remove it.
Norton also tells you exactly everything the program did (e.g. which deleted registry keys, how many times it started up by itself, what is blocked) since it had been monitoring it.
All of this is as a result of removing it from other people’s systems.
Also note the file is more than hidden. Even if you allow hidden files to be viewed simply going to appdata\local to delete it might not work. But you should try setting your folder options to view hidden (via control panel–>appearance and personalization—>folder options and seeing it it’s there. Always look at the date last modified if you do see a file there.
Good luck
Armando
May 27, 2011 @ 21:36:41
Easiest fix:
Jus change the date on your computer for 7 days ahead of
Current date. Restart; Gone!!!!
Edward
May 31, 2011 @ 13:15:37
I am an IT tech for a mid sized co. I mainly deal with hardware installtion and minor software. My boss recently had this problem with his laptop. Unfortunatelly he had already purchased the fake removal tool from the infected site. So the only way to remove after this was to have the PC scanned with a good virus scan and remval tool. Trying to restore it back a few days after he had already purchased the fake scan was impossible. If you get this messege on your PC the best thing to do is to not open or close any of the messeges and run the virus protection that you purchased or own on your PC. If anytime you get a messege that says you need to buy there product to remove a virus, it’s a scam don’t do it. And if your not sure the best thing to do is don’t touch anything and ask some one you trust to take a look at your PC. Most of the time it’s not fully infected to the point it cant be fixed. But once you open or purchase it then your probs. begin. Hope this helps
Henry
May 31, 2011 @ 14:40:58
Armando, You are right! It is the EASIEST way! :-)
Ramal
Jun 02, 2011 @ 08:11:53
Again,microsoft screws the consumer.There was another virus similar to this one last year and i’m sure we’ll have to keep dealing with them yearly until microsoft gets their act togethere.I can’t wait to switch to mac.
Alex
Jun 06, 2011 @ 18:26:24
Thanks all – will try the system restore tonight and report back
Alex
Jun 07, 2011 @ 08:19:40
Tried this last night, but there was no option for F8 when restarting, only F2 and F12 – neithere of which offer a ‘Repair Computer’ or ‘System Restore’ option. Nor am I able to start the computer in safe mode. I tried hitting/holding F8 on start up anyway, but nothing happened. Is it possible that the virus has prevented me from perfroming the system restore function?
Or am I just doing it wrong? :)
chelle
Jun 07, 2011 @ 20:28:38
we had this virus after looking in google images and know a freind who picked it up from there as well. we restored our system to and earlier date and it seems to have cleared. however the only worry is if there is anything still in the background of the computer watching for any sort of financial activity? Can anyone say if the restore method has cleared it completey. we did not click on buy when it came up and since restoring have managed to reinstall our macafee security?
Alex
Jun 09, 2011 @ 13:26:43
tried using the System Restore in Control Panel yesterday… of course the last restore point was after the date of infection – and there were no alternative dates! The work of the virus again? I don’t know.
Any advise would be gratefully received
Maddy
Jun 13, 2011 @ 05:09:01
Hey ! just put a good antivirus thing on a cd from a clean computer and then put it right into the infected comeputer. works goood
Ghislain
Jun 14, 2011 @ 21:59:02
I saw this thing on a friends computer sometime ago. In a matter of a few hours, she was stuck with the constant pop-ups and wasn’t able to launch much applications.
Here’s how I got rid of it, manually:
Restart the computer, hit the F8 key from right after POST and jump in safe mode.
Once there, open the Task Manager and look through the processes list. Normally in safe mode, only the essential processes are on, which should lead to a very small list of programs to look at. In my case, the malicious program was 3 letters long, and seemed to mean nothing whatsoever, like enl.exe or ypu.exe.
Next step, in the start menu search for regedit in the programs bar right over the start menu logo.
Once in the registry do a global search using as your keyword the name of the program, including the .exe. It should lead you to the extensions association list, on an entry located under the exeFile group I think. There you will have the path leading to the actual location of the file!
It also explains why, whichever program you try to start will immediately launch a pop-up. It bypasses the standard procedure for handling exe files and instead, tells windows: “Hey, to know what to do with any of em’ exe files, you must use that kjh.exe or apw.exe over there!”
(Note, if you know your way into the registry, you can start right away by searching under the .exeFile in the file association part)
Now, let’s put that registry aside a bit. To get everything back in order, you must delete the exe at its current location and while at it, why not clear off all the temporary files too. You should also make a regular search then and get rid of any other related files that are at different locations (shouldn’t be much)
Then the horrible part: you must reverse all the damaged registry keys back to their original values! You can do it by let’s say… compare it to that of another computer and match the values. Or by hitting this link:
http : //www.sevenforums.com/tutorials/19449-default-file-type-associations-restore.html
and saving the reg key for the EXE extension. Once you execute that on the affected computer, the keys will be restored to their original values!
Now the computer will be able to boot and work normally outside of safe mode! If you are at ease doing it, you can clean the registry by yourself by removing any entry involving the malicious programs name, or run a stardard anti-virus and anti-spyware scan to finish it up for you (and probably find more stuff).
I hope, that any part of this lengthy post can be of help to anyone here. And that I didn’t actually forget some important stuff XD
G
Junior
Jun 23, 2011 @ 04:04:27
Armando: Thanks it worked.
Tony
Jul 31, 2011 @ 14:30:14
Armando, Lisa and Junior have it right. Just change the date on your computer for 7 days ahead. I also followed up with Norton Erase Program. Has anyone seen the virus rear it’s ugly head again after this fix?