Description of Win 7 Anti-Spyware 2011 and consequences of its residing on your PC

A kit of downloading tools and methods is applied to propagate the infection. There are even facilities installing it, if user declines installation request.  That is, there is no single explanation of the way the rogue has been installed. In any case, should your PC have due protection, you would be notified either on infiltration attempt or that the content you are downloading is not of appropriate quality.
Remove Win 7 Anti-Spyware 2011 as yet another faking infection. Just like overwhelming majority of contemporary counterfeits, it plays a role of system security defender.

Win 7 Anti-Spyware 2011 Technical Details:

  • Full name: Win 7 Anti-Spyware 2011, Win7 Anti-Spyware 2011
  • Version: 2012
  • Type: Rogue anti-spyware
  • Origin: Russian federation

Signs of being infected with Win 7 Anti-Spyware 2011:

Sometimes there is no escape from the flow of alerts and nag screens by the adware. Sometimes its alerts are less intensive and cases happen when they are not shown at all for rather considerable period. That means Win 7 Anti-Spyware 2011 is a variable schedule program. Since its only business is to remind users of security issues to fix, the schedule varies in relation to the adware popups.
The adware tries to install its icon on the system tray and a shortcut on the desktop. While it is idle, i.e. show few or no popups, the above signs might be used to the purpose of its detection.
Anyway, the adware is available for automatic detection with free scanner:

Win 7 Anti-Spyware 2011 automatical removal:

If the advertisement infection is deleted, it does not mean that viruses are gone, as well as that there are any viruses to be gone. In the other words, automated detection of threats seems to be the only way to see if you have threats other than the adware in question to deal with.
Follow the link below to uninstall Win 7 Anti-Spyware 2011 and delete other threats as disclosed by free scanner.

Win 7 Anti-Spyware 2011 Removal Tool

Manual Removal of Win 7 Anti-Spyware 2011:

Besides advertising the fake antivirus by its annoying trialware the hackers take care of safety of successfully injected copies of the malware. This implies proactive measures when deletion attempt in relation to the adware entries is detected. In the wild, Safe Mode is a good fix in a situation when any application blocks its entries. Have your computer system in Safe Mode while removing Win 7 Anti-Spyware 2011 manually.

Remove Win 7 Anti-Spyware 2011 files and dll’s:

%AppData%\Local\<random 3 letters>.exe

Unregister Win 7 Anti-Spyware 2011 registry values:

HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’
HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1′ = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1″ %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’
HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1′
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1′
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’
HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1″ %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘

Win 7 Anti-Spyware 2011 Remover with free scan

Win 7 Anti-Spyware 2011