# Oh, crap, "Win 7 Security 2011" Has Completely Hijacked My System

**URL:** <https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488>\
**Category:** Factual Questions\
**Created:** [April 7, 2011, 3:21am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488 "2011-04-07T03:21:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![RickJay](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@RickJay](https://boards.straightdope.com/u/RickJay)\
**Post date:** [April 7, 2011, 3:21am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/1 "2011-04-07T03:21:01Z")

</div>

I can’t do anything. (On a work computer now.) Browser’s hijacked. Trying to run any executable simply brings up this damned trojan. Even regedit. What the hell do I do?

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [April 7, 2011, 3:32am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/2 "2011-04-07T03:32:11Z")

</div>

> **[Remove Vista Antimalware 2011 and Win 7 Antispyware 2011 name changing rogue...](https://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2011)**
>
> XP Guard, Vista Antispyware 2011, and Win 7 Antimalware are all names for the same rogue anti-spyware program. When this particular rogue is installed, it will install itself as a variety of different program names and graphical user interfaces...

---

<div class="post-metadata">

**Author:** ![Ferret\_Herder](https://avatars.discourse-cdn.com/v4/letter/f/e47774/32.png) [@Ferret\_Herder](https://boards.straightdope.com/u/Ferret_Herder)\
**Post date:** [April 7, 2011, 3:33am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/3 "2011-04-07T03:33:10Z")

</div>

[Recent Pit thread with advice.](http://boards.straightdope.com/sdmb/showthread.php?t=603406)

---

<div class="post-metadata">

**Author:** ![RickJay](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@RickJay](https://boards.straightdope.com/u/RickJay)\
**Post date:** [April 7, 2011, 3:44am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/4 "2011-04-07T03:44:54Z")

</div>

> [@yoyodyne](#):
>
> [Remove Vista Antimalware 2011 and Win 7 Antispyware 2011 name changing rogue (Uninstall Guide)](http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2011)

In some fun twists,

1. My OTHER computer insists every rkill link is itself a known virus and my work computer’s so secure I can’t get around that.

2. The instructions to remove the registry key don’t help because there is no registry key called “Win 7” anything. It’s called something else.

However, by following some of this advice I have Malwarebytes running. Fingers crossed.

Fucking virus fucks. How do the cops not catch these people?

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [April 7, 2011, 4:04am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/5 "2011-04-07T04:04:06Z")

</div>

The registry keys are listed on the bleepingcomputer page.

---

<div class="post-metadata">

**Author:** ![md2000](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@md2000](https://boards.straightdope.com/u/md2000)\
**Post date:** [April 7, 2011, 12:47pm UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/6 "2011-04-07T12:47:36Z")

</div>

Some suggestions - worst case, unplug the hard disk, plug it into another PC as a second drive, and see if you can run the antivirus on it that way. You might also try loading the registry remotely on your home network from another PC, if the remote procedure calls are not disabled. Commercially, the simplest thing is to hook up the drive on another PC, recover all data (My Documents, email folders, etc.) and then reformat the drive and reinstall the OS. Faster and quicker than fighting with it.

---

<div class="post-metadata">

**Author:** ![Sister\_Vigilante](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@Sister\_Vigilante](https://boards.straightdope.com/u/Sister_Vigilante)\
**Post date:** [April 7, 2011, 5:59pm UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/7 "2011-04-07T17:59:11Z")

</div>

This happened to me twice, once at work and once at home even though at home I didn’t even have IE up - it hijacked me anyway.

Get malwarebytes onto a USB drive from an uninfected computer, disconnect completely from internet, run malwarebytes from the drive. Worked both times.

---

<div class="post-metadata">

**Author:** ![RickJay](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@RickJay](https://boards.straightdope.com/u/RickJay)\
**Post date:** [April 8, 2011, 12:02am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/8 "2011-04-08T00:02:39Z")

</div>

> [@yoyodyne](#):
>
> The registry keys are listed on the bleepingcomputer page.

Malwarebytes fixed it. I had to change its name to iexplore, but it ran then, and killed the infection. Very strange; I had AVG running and haven’t been doing anything risky.

However, none of the bleepingcomputer advice was correct. None of the processes they said would be in the Task Manager were there; the registry entries they said to look for did not exist. I guess the author of the virus changed it up.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [April 8, 2011, 3:32am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/9 "2011-04-08T03:32:18Z")

</div>

Try booting into Safe mode and running System Restore. It does a decent job much of the time.

To boot into Safe Mode, press the F8 key multiple times before you see the “Starting Windows” screen. You will go to a black screen. Use the down arrow to highlight “Safe Mode with Networking” and press Enter. When you log in, you’ll see an option to go to System Restore. Use it, and choose a restore date that’s before you had the problem.

This doesn’t always work, but lately malware hasn’t bothered to screw with Safe Mode or System Restore. It was not very useful five years ago, but I’ve had good success with it lately.

Once you get your computer back, run Malwarebytes.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [April 8, 2011, 10:28am UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/10 "2011-04-08T10:28:25Z")

</div>

> [@RickJay](#):
>
> Fucking virus fucks. How do the cops not catch these people?

Because they are in the Ukraine, or some other non-US jurisdiction. And the internet cops are in on it.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [April 8, 2011, 12:34pm UTC](https://boards.straightdope.com/t/oh-crap-win-7-security-2011-has-completely-hijacked-my-system/577488/11 "2011-04-08T12:34:04Z")

</div>

> [@Fear\_Itself](#):
>
> Because they are in the Ukraine, or some other non-US jurisdiction. And the internet cops are in on it.

Not only that, but they are designed so that they won’t install on any computer whose language is set to “Russian” (or “Ukranian,” if there is such a setting). Thus, it doesn’t install on any computers in the country where they base their operations, and local officials have no reason to be involved.
