Thread Rating:
  • 1 Vote(s) - 4 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[TUT]Removing Vista Security 2011[/TUT]
#1
This is just a short tutorial of removing Vista Security 2011, without having to go take a risk of changing your registry settings. I don't know if this works with other rogue anti-viruses.

Yes you can use scanners like MalwareBytes', SUPERantispyware, ESET Online Scanner, etc. However, what if the virus doesn't allow you to access the internet?

I am going to use my friend's situation as an example:

[Image: unledwe.jpg]

There are a lot of processes, but one of these processes is the rogue anti-virus. Do you see it? You can easily identify the rogue anti-virus program in your Windows Task Manager.

In the above picture, the "Vista Security 2011" is none other than itn.exe. How do I know this? Well, the antivirus disguised itself as a process, to be a 3 letter word .exe file. So in this case it would be itn.exe. The process should be 15,000 K or below. Also, look at the description.

File Name: itn.exe
Description: itn


This makes it suspicious doesn't it?
  • Now right-click on the process and click "Open File-Location". A folder will come up, and you should be in the AppData\Local folder. If not, then navigate to:


    C:\Users\USER(Well, your name if you renamed it)\AppData\Local\.


  • Now go back to your task manager, and end the process.

The anti-virus is gone because it is not running anymore, however it will keep coming back when you restart your system. So we have to delete this file permanently.

Now go back to the folder. That is where Vista Security hides itself. You can't see the exe file right? That is because it is hidden.

Now, in this "Local" folder, you're going to have to change your settings a little.
  • Click on Organize
  • And then click on "Folder and Search Options"
  • Then go to the "View" tab.
  • 1. Choose "Show Hidden Files, Folders, and Drives"
  • 2. Uncheck "Hide protected operating system files"
  • 3. Uncheck "Hide extensions for known file types"
  • Then press OK.

By doing this, you will now see all of the files that are hidden.

In my case, I'm looking for itn.exe and I found it:

[Image: vvvld.jpg]


Now that is the application that has been on your computer. This is to run Vista Security. Next steps:
  • Click on the file ONCE so that you are able to highlight the file.
  • On your keyboard, hit the Shift+Delete button.

By hitting the Shift+Delete button, you are able to permanently delete the file instead of having to send it to the Recycle Bin.

"Vista Security 2011" should now be deleted from your computer. You can do a scan just to make sure. You should now be able to access the internet.

Remember to rehide your files again.
  • As you're in the "Local" folder, click on Organize
  • And then click on "Folder and Search Options"
  • Then go to the "View" tab.
  • 1. Unchoose "Show Hidden Files, Folders, and Drives"
  • 2. Check "Hide protected operating system files"
  • 3. Check "Hide extensions for known file types"
  • Then press OK.
HJT Team. Deltron <3 RDCA <3 Quintus <3
Reply
#2
I still prefer my method. Tongue

Great tutorial, nonetheless.
Reply
#3
LOL WOW. I had to remove my friends vista security 2011 in a three day process, and we had the virus not too long ago. You could have posted this earlier. But anyways that is NOT the correct removal process. You must download and install MalwareBytes Anti-Malware and register it to get full protection and "realtime" scanning. It will remove all 295 infections. This tutorial only show you how to remove several...
[Image: t5BWm.png]
Reply
#4
(05-08-2011, 03:17 PM)The High Roller Wrote: LOL WOW. I had to remove my friends vista security 2011 in a three day process, and we had the virus not too long ago. You could have posted this earlier. But anyways that is NOT the correct removal process. You must download and install MalwareBytes Anti-Malware and register it to get full protection and "realtime" scanning. It will remove all 295 infections. This tutorial only show you how to remove several...

That's why I included to scan AFTER just incase. Sometimes the rogue anti-virus won't allow people to access the internet. So if that's the case, then how can you download MalwareBytes' on the infected PC? This is a tutorial just incase the victim is not allowed to gain access to the internet.

And how do you get the ID and Key to register MalwareBytes'? I want to register mine o.o.

Downloading and installing MalwareBytes' to a CD or USB drive and then accessing it on the infected system is kinda complicated for a beginner user.

Since this tutorial allows you to remove the program, you can now access the internet and do whatever you want with the scanners; you get what I mean?
HJT Team. Deltron <3 RDCA <3 Quintus <3
Reply
#5
You realize MBAM doesn't detect all infections, right?
Reply
#6
(05-08-2011, 03:50 PM)Deltron Wrote: You realize MBAM doesn't detect all infections, right?

Nothing detects all infections, Deltron. It is just that MalwareBytes has a high detection rate, and well, it proved enough to me that it can take care of the job. Don't think thats the only thing I used, I had ESET Online Scanner and 2 other scanners after that. After one MBAM scan, about 3-4 empty registry keys were left behind by the malware and SuperAntiSpyware cleaned it up... I think my friend was cleaned after that ESET Scan.
(05-08-2011, 03:28 PM)Brandenx781 Wrote: That's why I included to scan AFTER just incase. Sometimes the rogue anti-virus won't allow people to access the internet. So if that's the case, then how can you download MalwareBytes' on the infected PC? This is a tutorial just incase the victim is not allowed to gain access to the internet.

And how do you get the ID and Key to register MalwareBytes'? I want to register mine o.o.

Downloading and installing MalwareBytes' to a CD or USB drive and then accessing it on the infected system is kinda complicated for a beginner user.

Since this tutorial allows you to remove the program, you can now access the internet and do whatever you want with the scanners; you get what I mean?

Oh most definetly, I got what you mean. I have to get MBAM onto an isolated disc from my laptop, good idea.
[Image: t5BWm.png]
Reply
#7
Another solution: Restart your computer, Run malware bytes. and remove it. or use the registry editor
Reply
#8
Another solution, go with Windows 7 upgrade ;P
A developer, thinker & bliss guy that tries his hardest to enjoy life ~~~
Reply
#9
(02-01-2012, 07:49 AM)///ViNcE Wrote: Another solution, go with Windows 7 upgrade ;P

Which is equally as vulnerable to Windows 7 Security 2012, and multiple other viruses as it's a prime target.
Quaero gloria stellarum.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Top 43 Cyber Security Tools to Improve Your Network Security tk-hassan 0 634 01-29-2020, 04:00 AM
Last Post: tk-hassan
  [TUT] Securing Your Email Address Omniscient 60 20,552 09-30-2019, 01:02 AM
Last Post: samsmith001
  [TUT] How to tell if you're infected, and what to do N3w_2_H@Ck1n™ 61 21,194 02-02-2012, 06:49 PM
Last Post: 6+9=♋
  [Tut] Ultimate Guide To Protect Youself Blixx 25 5,776 12-21-2011, 12:03 PM
Last Post: DaUB3R
  [TUT]Great USB tools and how to use them caspur 14 5,295 11-27-2011, 09:42 AM
Last Post: Hei

Forum Jump:


Users browsing this thread: 1 Guest(s)