Description of Win 7 Anti-Virus 2011 and consequences of its residing on your PC

Win 7 Anti-Virus 2011 is a threat   to be removed above all for computer security reasons. Other matters are important as well, especially that users get annoyed with its informational influence. Even worse, if they trust the misleading software and decide to acquire its full version, they waste money into annoying scamware.
Some IT experts provide, and suggest using, cracks for registration of the adware. They say the registered version of the program is easier for extermination.   In the wild, the registration only enables the  adware to establish  or enhance web-connection to remote computer and get updated. The scam is not over after registration as there are plenty of other directions for its development.
Win 7 Anti-Virus 2011 Technical Details:

  • Full name: Win 7 Anti-Virus 2011, Win7 Anti-Virus 2011, Win7 AntiVirus 2011
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian federation

Signs of being infected with Win 7 Anti-Virus 2011:

Desktop alerts used by the adware are the same as Windows system alerts, if to compare their graphics. Furthermore, the adware tries to detect version of Windows (if infected OS is Windows) in order to shown alerts in graphics corresponding to the version of operating system.
In the meantime, it may alternate design  of its popups appearance and in sessions may provide no popups titled in a way clearly identifying the adware name or containing its name occurrences in the message  body.
Win 7 Anti-Virus 2011 automatical removal:

Infections of advertising kind are on the surface. Their detection is quite simple; moreover, in most of the cases it is rather impracticable to be unaware of the adware, if it is installed.
Manual Removal of Win 7 Anti-Virus 2011:

To uninstall Win 7 Anti-Virus 2011 is what users try to do after learning its malignant and dangerous essence. However, as a matter of fact, removing is not equal to uninstalling as the former implies complete eradication of removed object, unlike the latter. The point is that you can only uninstall the adware in question removing it for the adware does not allow users merely uninstall it. Because of the tricky program impact it is IT expert’s common suggestion to remove Win 7 Anti-Virus 2011 in Safe Mode (in Windows).

Remove Win 7 Anti-Virus 2011 files and dll’s:

%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe

Unregister Win 7 Anti-Virus 2011 registry values:

HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’
HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1’ = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1” %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’
HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’
HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1” %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1” %*’
HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’
HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “%1” %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\<random 3 letters>.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘

