Win 7 AntiMalware 2011 is a clone of the recent rogue anti-spyware programs from infamous family of rogues that has been noticed in the middle of November. This new variant, Win 7 AntiMalware 2011, appears to have almost identical GUI and tricky methods applied that are dedicated for stealing the money. Win 7 AntiMalware 2011is distributed through phony online security scanners, fraudulent domains and flash updates that foolishly ask to be installed for watching a video. Clicking on those ads will automatically install Win 7 AntiMalware 2011unregistered version on your PC.
When inside, Win 7 AntiMalware2011 additionally creates a number of files, so that it can detect them as infections afterwards. To show you how “hard” your computer is infected, malware starts scanning the system and triggers its deceptive popup ads and notifications, for example:
Having done all this in fact worthless and misleading campaign, Win 7 AntiMalware2011 attempts to scare its victims into purchasing its license. However, these parasites are non-existent or harmless your system files, so you can be sure that you don’t need to pay any attention to them. Only Win 7 AntiMalware2011, which will continue its trying to insist you on your registering its commercial software should be eliminated. Keep in mind that it is incapable to help you with any virus threat. In fact, you should don’t hesitate and remove Win 7 AntiMalware 2011.
UPDATE!!! One of PC security bloggers, S!Ri, has announced about a serial code that may help you to disable those malwares that all change their names according to OS they find. Enter this serial code when doing Win 7 AntiMalware 2011 registration: 145-17884799-7733. This and the order number 21197673 should also work for earlier versions of this type of parasite. After typing them, you should become able to use your anti-spyware, if it fails follow the guide written below. Be aware that these numbers are expected to change in the near future!
To remove Win 7 AntiMalware 2011you will need another PC, as removing it from safe mode with networking will not work in most of the cases.
a) Burn these programs to CD or write them to USB disk. You can use your MP3 player, or smartphone if it has storage functions. This parasite does not spread through USB at the moment:
1. STOPzilla or an automatic removal tool below. Update STOPzilla and run a full system scan.
2.You might want to download Hitman Pro or Malwarebytes as alternate scanners. Though you are likely to be able to download them later on.
b) Boot normally. wait for Win 7 AntiMalware 2011 to launch, and run exeregfix.reg . This should allow launching legitimate programs
c) Delete or remove the files that are mentioned in our files box. You can use STOPzilla to identify the infected files and additional infections or automatic Win 7 AntiMalware 2011removal tool. Do not forget update it before scanning. Remove what it finds.
d) Scan with STOPzilla and secondary tools and reboot your PC. This should fully get rid of Win 7 AntiMalware 2011.
Win 7 AntiMalware 2011 manual removal:
Delete registry values:
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CURRENT_USERSoftwareClassespezfileshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CLASSES_ROOT.exeshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CLASSES_ROOTpezfileshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesMozilla Firefoxfirefox.exe"
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellsafemodecommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesMozilla Firefoxfirefox.exe" -safe-mode
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetIEXPLORE.EXEshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesInternet Exploreriexplore.exe"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "FirewallOverride" = "1"
%UserProfile%Local SettingsApplication DataopRSK
%UserProfile%Local SettingsApplication Datapw.exe
%UserProfile%Local SettingsApplication DataMSASCui.exe