Description: Personal Internet Security 2011 is another rouge anti-spyware program just like Personal Security Sentinel, Internet Antivirus 2011 and Internet Security Suite. Once this program gets access to a system, it will perform fake scans and will come up with a list of infections claiming that the user needs to purchase the paid version of the program to remove those threats.
But the fact is the files that Personal Internet Security 2011 will identify as “threats” are originally created by the program itself only to mislead the user. In reality these files are no threat to the system. Beside these detections, Personal Internet Security 2011 will also come up with pop up ads and notification claiming that the machine is infected by malicious programs. But these messages are nothing but hoax. In order to convince the user that his or her system has got infected by malicious programs, this rouge software will display this sort of warning messages:
Personal Internet Security 2011 FAKE error messages you may see.
“Warning
Warning! Virus detected
Threat Detected: Trojan-Spy.HTML.Sunfraud.a”
Personal Internet Security 2011
» Download Personal Internet Security 2011 Removal Software
Now if you think your computer has gotten infected by Personal Internet Security 2011 then you should take necessary steps as soon as possible to remove Personal Internet Security 2011 from the machine. There are both automatic and manual Personal Internet Security 2011 removal procedures available which should help you out with this. .
Remove Proxy Setting so You Can Connect to the Internet Again.
Please take a quick second and hit the FaceBook Like button on the top of this page.
Personal Internet Security 2011: Manual Removal procedure
In case of the manual removal procedure, at first you need to stop the following process(s):
- PersonalIS2011.exe
- lssra_259.exe ( Will most likely be unquie file trace )
You may find only one of these processes running in your machine. To stop the above mentioned process, you need to go to the file location and then have to re-name the file. After that, the computer has to be restarted and then you will have to browse to the file location and delete the file.
Once that is done, you will have to get rid of these files:
For Windows XP
C:\Documents and Settings\All Users\Application Data\Unique File Trace\
C:\Documents and Settings\All Users\Application Data\Unique File Trace\WKsra_249.exe
C:\Documents and Settings\All Users\Application Data\Unique File Trace\35.mof
C:\Documents and Settings\All Users\Application Data\Unique File Trace\[SET OF RANDOM CHARACTERS].dll
C:\Documents and Settings\All Users\Application Data\Unique File Trace\[SET OF RANDOM CHARACTERS].ocx
C:\Documents and Settings\All Users\Application Data\Unique File Trace\MSSSys\
C:\Documents and Settings\All Users\Application Data\SMEYFE
C:\Documents and Settings\Application Data\Personal Internet Security 2011\
C:\Documents and Settings\Application Data\Personal Internet Security 2011\Instructions.ini
C:\Documents and Settings\Application Data\Personal Internet Security 2011\cookies.sqlite
C:\Documents and Settings\All Users\Application Data\Unique File Trace\
C:\Documents and Settings\All Users\Application Data\Unique File Trace\7377.mof
C:\Documents and Settings\All Users\Application Data\Unique File Trace\80e9877130a15854a99bf6dd8d368239.ocx
C:\Documents and Settings\All Users\Application Data\Unique File Trace\mozcrt19.dll
C:\Documents and Settings\All Users\Application Data\Unique File Trace\PersonalIS2011.exe
C:\Documents and Settings\All Users\Application Data\Unique File Trace\PIS.ico
C:\Documents and Settings\All Users\Application Data\Unique File Trace\sqlite3.dll
C:\Documents and Settings\All Users\Application Data\Unique File Trace\unins000.dat
C:\Documents and Settings\All Users\Application Data\Unique File Trace\PISSys\
C:\Documents and Settings\All Users\Application Data\Unique File Trace\Quarantine Items\
C:\Documents and Settings\All Users\Application Data\PIKKS\
C:\Documents and Settings\All Users\Application Data\PIKKS\PIQBS.cfg
C:\Documents and Settings\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Internet Security 2011.lnk
C:\Documents and Settings\Desktop\Personal Internet Security 2011.lnk
C:\Documents and Settings\Start Menu\Personal Internet Security 2011.lnk
C:\Documents and Settings\Start Menu\Programs\Personal Internet Security 2011.lnk
For Windows Vista / Windows 7
C:\Users\YOUR USER NAME\AppData\Unique File Trace\
C:\Users\YOUR USER NAME\AppData\Unique File Trace\WKsra_249.exe
C:\Users\YOUR USER NAME\AppData\Unique File Trace\35.mof
C:\Users\YOUR USER NAME\AppData\Unique File Trace\[SET OF RANDOM CHARACTERS].dll
C:\Users\YOUR USER NAME\AppData\Unique File Trace\[SET OF RANDOM CHARACTERS].ocx
C:\Users\YOUR USER NAME\AppData\Unique File Trace\MSSSys\
C:\Users\YOUR USER NAME\AppData\SMEYFE
C:\Users\YOUR USER NAME\AppData\Unique File Trace\7377.mof
C:\Users\YOUR USER NAME\AppData\Unique File Trace\80e9877130a15854a99bf6dd8d368239.ocx
C:\Users\YOUR USER NAME\AppData\Unique File Trace\mozcrt19.dll
C:\Users\YOUR USER NAME\AppData\Unique File Trace\PersonalIS2011.exe
C:\Users\YOUR USER NAME\AppData\Unique File Trace\PIS.ico
C:\Users\YOUR USER NAME\AppData\Unique File Trace\sqlite3.dll
C:\Users\YOUR USER NAME\AppData\Unique File Trace\unins000.dat
C:\Users\YOUR USER NAME\AppData\Unique File Trace\PISSys\
C:\Users\YOUR USER NAME\AppData\Unique File Trace\Quarantine Items\
C:\Users\YOUR USER NAME\AppData\PIKKS\
C:\Users\YOUR USER NAME\AppData\PIKKS\PIQBS.cfg
Personal Internet Security 2011 Registry Removal Proedures
After getting rid of the traces you will have to eliminate the infected registry items too as the registry should remain clean from all sorts of harmful applications. You will have to remove or modify the following registry values:
- HKEY_CLASSES_ROOT\PersonalIS.DocHostUIHandler
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:25553"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Internet Security 2011"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
- HKEY_CURRENT_USER\Software\3
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CLASSES_ROOT\PersonalIS2011.DocHostUIHandler
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:25401'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = '7'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "88780570603"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Internet Security 2011"HKEY_CURRENT_USER\Software\Microsoft\Internet
- Explorer\Download "CheckExeSignatures" = 'no'
It is strongly recommended that you run a complete virus scan for your system once you are done with the Personal Internet Security 2011 Removal procedure. To do that, we recommend using Spyware Doctor with Antivirus.
Personal Internet Security 2011 Directories:
Windows XP
- C:\ProgramFiles\Personal Internet Security 2011
Windows Vista/7:
- C:\ProgramFiles(x86)\Personal Internet Security 2011
Outside Resources:
http://en.wikipedia.org/wiki/Personal_Internet_Security_2011
Speak Your Mind