I got a virus called "Win 7 antivirus 2012" It killed my win defender

computergeekguy

New member
I got a virus called "Win 7 antivirus 2012" It killed my win defender

A few days ago i got the nastiest virus on my machine i have ever seen.

It didn't slow my machine down any due to my having more cores and ram than i could ever use :cool:

But it got all executable files and redirected them to the virus. :mad:

It also new exactly were to hit my comp disabling my internet explorer\firefox killing my windows defender getting through my firewall and disabling most control panel programs.

I was able to get my comp back thanks to this website
i had to look at in on i different comp though.
Remove Win 7 Antispyware 2012 and Vista Antivirus 2012 name changing rogue (Uninstall Guide)

It saved me disabling the virus long enough too get control of my comp to resolve the problem.

But sadly the virus damaged my windows defender and it has not recovered.

I went to the windows website to download windows defender but Microsoft wont install it due to it thinking it is already installed.

It is not listed in add\remove programs.

I looked in turn windows features on or off and it was non existent there as well.

So after a long day of head banging i called it a day.

At least i got my comp back up to full speed :D

So if you guys have some pointers i would be appreciative :)

P.S. From my experience it was pretty complex. It knew exactly were to hit plus it posed as an anti virus program so a less experienced person would have believed it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
7 home premium 64 bit
CPU
AMD Phenom II X6 1055T
Motherboard
Asus M4A785TD-M EVO
Memory
DDR3 1333 6144 MBytes each modual 2048 mb
Graphics Card(s)
Power Color ATI R9 270x bluescreen edition
Sound Card
s/pdif part of my motherboard
Monitor(s) Displays
It is a 42" lcd tv :D
Screen Resolution
1920 X 1080
Hard Drives
Samsung 120gb SSD (EVO 840)
Hitachi 500gb 3gb\s sata hard drive, slow boring but gets the job done
PSU
Orion 585w psu Model# HP585D (updated to EVGA 600W)
Case
A shoebox
Cooling
Box fan....
Keyboard
I telepathically convay what I want said.
Mouse
Cat
Internet Speed
Loading...
Antivirus
A facial mask
Browser
Firefail, Internet Exploder
Other Info
I love my gaming rig, FreeCell and Solitaire never looked so good.

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Asus Build
OS
Microsoft Windows 8.1 Pro 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
B85M-E
Memory
8.00 GB
Graphics Card(s)
None
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Asus 23.6" Monitor
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
INTEL SSDSC2BW180A4
Samsung SSD 840 PRO Series
PSU
Seasonic S12II-380Bronze
Case
Lian Li
Cooling
Fan, Passive
Keyboard
Logitech K120
Mouse
Microsoft Touch Mouse
Internet Speed
4ms Ping, 19.0 Mbps Download, 19.0 Mbps Upload
Antivirus
Eset Endpoint
Browser
Internet Explorer, Chrome
Thanks for the reply i will look into those links.

As for me i am pretty sure i got rid of the hole thing

I use very safe internet browsing habits with firewall etc etc. I just got on the internet to Google up some history about wwII and the next thing i know win 7 antivirus 2012 gets on there and starts making a mess of my comp.

As for antivirus i went with windows defender and spybot search & destroy for most of my probs but after this virus i got malwarebytes trial addition avg and a few other things. Just trying things out to see what i like :)

All my safety stuff designed by windows got ether disabled or trashed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
7 home premium 64 bit
CPU
AMD Phenom II X6 1055T
Motherboard
Asus M4A785TD-M EVO
Memory
DDR3 1333 6144 MBytes each modual 2048 mb
Graphics Card(s)
Power Color ATI R9 270x bluescreen edition
Sound Card
s/pdif part of my motherboard
Monitor(s) Displays
It is a 42" lcd tv :D
Screen Resolution
1920 X 1080
Hard Drives
Samsung 120gb SSD (EVO 840)
Hitachi 500gb 3gb\s sata hard drive, slow boring but gets the job done
PSU
Orion 585w psu Model# HP585D (updated to EVGA 600W)
Case
A shoebox
Cooling
Box fan....
Keyboard
I telepathically convay what I want said.
Mouse
Cat
Internet Speed
Loading...
Antivirus
A facial mask
Browser
Firefail, Internet Exploder
Other Info
I love my gaming rig, FreeCell and Solitaire never looked so good.
Geek,

defender is automatically disabled (becomes obsolete) when an antivirus is installed. However, you are only ever supposed to have 1 antivirus installed at a time (Malwarebytes isn't an antivirus and is fine to be coupled with an Antivirus program). The reason is that they tend to 'get in the way' of each other and can cause even more problems, including being less effective and running over each other.

Also, you should only remove them with their uninstaller tool (can google uninstaller tool avg as an example for avg). I recommend never using AVG as it is just terrible. It alone causes its own set of issues, many of which I've had to help others fix. And can't spybot search and destroy be a bit vigorous and overpowerful? Be very careful when using it, you might delete something you'll regret.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Asus Build
OS
Microsoft Windows 8.1 Pro 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
B85M-E
Memory
8.00 GB
Graphics Card(s)
None
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Asus 23.6" Monitor
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
INTEL SSDSC2BW180A4
Samsung SSD 840 PRO Series
PSU
Seasonic S12II-380Bronze
Case
Lian Li
Cooling
Fan, Passive
Keyboard
Logitech K120
Mouse
Microsoft Touch Mouse
Internet Speed
4ms Ping, 19.0 Mbps Download, 19.0 Mbps Upload
Antivirus
Eset Endpoint
Browser
Internet Explorer, Chrome
use avira it has a high detection rate for a free antivirus
Avira anti-virus for private users
click were it says avira free antivirus not the paid for ones and if it ask you to do a survey just deny it and get the free one
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 10 64bit
CPU
AMD Phenom II X4 925 (Deneb)(2.8GHz) OC 3.4GHz
Motherboard
M5A78L-MLX Plus
Memory
Corsair Vengeance DDR3 4GBX2 (8192MB)
Graphics Card(s)
XFX HD 6870 1GB (OC)- 940MHz core, mem 1150MHz
Monitor(s) Displays
Vizio 26' 1920x1080 / Acer 1336x768
Screen Resolution
1920x1080 60Hz /1336x768
Hard Drives
Kingston Digital 60GB SSDNow V300/500gb HDD Western Digital 7200rpm (/WD 160GB HDD 7200rpm
PSU
CORSAIR CX600 600w
Case
AZZA Orion 202 EVO
Cooling
cooler master hyper TX3 cpu cooler
Keyboard
Razer DeathStalker
Mouse
Logitech Optical Gaming Mouse G400
Antivirus
Defualt on win 10
Browser
Firefox
Other Info
cpu is overclocked in bios

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks for all of your replies

I tried the elevated command prompt in verifyonly mode and it came up with nothing

If this helps any when i try to start windows defender i get: "The specified service does not exist as an installed service. (Error Code:0x80070424)

Meanwhile i will look into seeing if i can ether replace missing files or reinstall from the win defender on another comp
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
7 home premium 64 bit
CPU
AMD Phenom II X6 1055T
Motherboard
Asus M4A785TD-M EVO
Memory
DDR3 1333 6144 MBytes each modual 2048 mb
Graphics Card(s)
Power Color ATI R9 270x bluescreen edition
Sound Card
s/pdif part of my motherboard
Monitor(s) Displays
It is a 42" lcd tv :D
Screen Resolution
1920 X 1080
Hard Drives
Samsung 120gb SSD (EVO 840)
Hitachi 500gb 3gb\s sata hard drive, slow boring but gets the job done
PSU
Orion 585w psu Model# HP585D (updated to EVGA 600W)
Case
A shoebox
Cooling
Box fan....
Keyboard
I telepathically convay what I want said.
Mouse
Cat
Internet Speed
Loading...
Antivirus
A facial mask
Browser
Firefail, Internet Exploder
Other Info
I love my gaming rig, FreeCell and Solitaire never looked so good.

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
Thanks guys for all of your help i have done a little researching about windows defender and there was a similar person that got exact same virus and it killed windows defender on his as well.

I will look into Microsoft security essentials and i think i will give up on windows defender due to i got a virus on another machine today and windows defender was pretty worthless on both accounts.

P.s. WHAT IS UP WITH ALL THESE VIRUSES i have never in my life had such a problem as i have this week and i practice very safe browsing techniques. And on both instances it has been a huge battle for hours on end fighting to get my comp back.

Both viruses deleted windows shortcuts disabled programs and have been putting up one heck of a fight.

I'm sorry if i sound aggravated but wouldn't you if you recovered from one virus just to get nailed by a nastier one the next day?

Luckily for me Ive almost got virus number 2 beaten but i still have some work before i can declare complete victory. :picnic:

But anyway thank you for your advice and help.

m.s.e. will probably be a good addition to my security system :)

And BE CAREFUL ON THE INTERNET these viruses have proven to be very sneaky! Even for the more advanced of security systems.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
7 home premium 64 bit
CPU
AMD Phenom II X6 1055T
Motherboard
Asus M4A785TD-M EVO
Memory
DDR3 1333 6144 MBytes each modual 2048 mb
Graphics Card(s)
Power Color ATI R9 270x bluescreen edition
Sound Card
s/pdif part of my motherboard
Monitor(s) Displays
It is a 42" lcd tv :D
Screen Resolution
1920 X 1080
Hard Drives
Samsung 120gb SSD (EVO 840)
Hitachi 500gb 3gb\s sata hard drive, slow boring but gets the job done
PSU
Orion 585w psu Model# HP585D (updated to EVGA 600W)
Case
A shoebox
Cooling
Box fan....
Keyboard
I telepathically convay what I want said.
Mouse
Cat
Internet Speed
Loading...
Antivirus
A facial mask
Browser
Firefail, Internet Exploder
Other Info
I love my gaming rig, FreeCell and Solitaire never looked so good.
One thing I'll add is that one of the people I thought I had cleaned this sucker off of had it come back about a week later. (Or maybe she just got reinfected...) The second time around I did deep scans with several different standalone virus sweepers. The first one (Malwarebytes) cleaned a bunch of stuff out. A later pass with the standalone version of MSE (from a bootable CD) found remnants of it in her Java cache. First thing I did when I got back to my computer was clean my own Java cache - just in case. :geek:
 

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
I don't get hit with any! In fact if any old download contains a bug hidden in a zip file but never opened like a few found here for old XP utilities the present av program will find and remove them completely. It also sees an effective firewall with web filtering.

Another free tool however you can add on to alert you to bad sites which is one reason you are seeing more then one is called Web of Trust which is an IE addon that flags bad sites with a red icon. Now places like SF of course will see a green one for safe! :D
 

Attachments

  • Web of Trust Icon.jpg
    Web of Trust Icon.jpg
    12.4 KB · Views: 158

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer
WOT is great. I stuck that and Firefox on the machine belonging to the person I mentioned above. :)
 

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
Computer guy,

Windows Defender is not an antivirus, and never was. naturally its effectiveness in removing viruses will be limited. Think medieval shield against missles. Not everyone is gunna shoot ya, but when they do... Ka-Boom. Sheild won't save you.

Virus found in the Java cache directory

I would just remove java though, too dangerous. Recent java attacks have been reported, but they should have released an update for it (java).

I meantioned that I was infected myself with a similar (if not the same) virus, even with MSE. MSE caught it after an update and removed it, but it was via java. As I never use java, I have just removed it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Asus Build
OS
Microsoft Windows 8.1 Pro 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
B85M-E
Memory
8.00 GB
Graphics Card(s)
None
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Asus 23.6" Monitor
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
INTEL SSDSC2BW180A4
Samsung SSD 840 PRO Series
PSU
Seasonic S12II-380Bronze
Case
Lian Li
Cooling
Fan, Passive
Keyboard
Logitech K120
Mouse
Microsoft Touch Mouse
Internet Speed
4ms Ping, 19.0 Mbps Download, 19.0 Mbps Upload
Antivirus
Eset Endpoint
Browser
Internet Explorer, Chrome
The WDefender was simply a rather weak antispyware tool compared to other programs just so Windows would have something if a user never installed any protections at all and still browsed the web.

AVG and Clam av each came up with their own version of an IE security bar to alert to bad sites you would use along with WOT as adding a layer of protection without cost. The Crawler Toolbar doesn't require the Clam av to be installed however while with AVG the toolbar is an option along with the free version of the program.

Web filters and av but still no anti-malware protections. No anti--rootkit blockers for one example. For that you add one or two more programs on and you may have a strong shield? Or the detection and removal still isn't quite there yet. Java, Adobe, and other things often need updates since those will have flaws and let things in.

The best defense turns out to be the best offense by filtering bad sites using a program that detects and flags malicious code immediately. You'll tend to find this more in the retail programs however for internet security as well as having a good firewall inplace.

The other thing is having a program that can effectively spot changes like recoding attempts by malwares in files system and otherwise on the drive(s). Once you have any infection consider all system restores infected as well and turn off the System Restore feature until all traces are removed. If you can create and store a full system image that's even better since you won't have any worry about wiping your drive clean.
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer
Once you have any infection consider all system restores infected as well and turn off the System Restore feature until all traces are removed
This really isn't a good idea ... if something should go wrong during the cleaning of malware, a 'dirty' restore point to return to is better than nothing at all :geek:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It greatly depends on the malware itself. The usual recommend for viruses especially the self replicating type is dumping all restore points once you have the bug totally removed and manually create a few new ones to start off with. You wouldn't be worried about restore points while the machine is still seeing an active infection of some type.

The first thing I would recommend for any one with an extra drive and enough space available running 7 is to create a full system image to keep safe on the other drive. The reason being some of these newer fake antivirus/antispyware programs will effectively break the present Windows installation on a machine despite a complete removal of the malware itself.

I've run into this lately on a few systems where the system registry was too far gone even with the fake program/I-Worm completely gone the installation was unusable. Some of these malwares now being seen are far more advanced in how they work. Unless you can manually go through the entire registry once struck by one of these to find all the changes made a restore point would also have to be considered possibly toxic as well resulting in reinfection.

On one machine the I-Worm that looked just like a spyware remover went as far as creating a new admin account to lock the user/owner out totally! We managed to get into safe mode long enough to create a desktop shortcut for the VIPRE Rescue Program one of the more effective stand alone(doesn't install - runs completely out of temp folder).

That was able to clean up the Windows install seeing the bogus admin account deleted and later the drive was swept with the main av program but the copy of Windows on at the time was done for! That was seen on an older XP machine and later on a Vista laptop where again the I-Worm/fake program was totally removed but you couldn't use the Windows installation there either.

Once the drives on each machine were wiped and adequate protections were added on neither one has had any further malwares to be concerned about. But it did show that some of them are better written with the intent to make the OS unusable after any infection. And sure enough too many problems suddenly appeared after that malware was long gone!

This is where having a disaster recovery plan of some type is best advised. If the malware buries itself too deep you can be faced with the need to wipe the drive and start over fresh if you don't have an image you can restore. It stinks for those running one drive systems without an external drive for an image or simply to back things up on.

On that XP desktop I had to download the VIPRE RP and transfer it manually over to the infected machine by way of a flash drive since you couldn't even get online in safe mode with due to the bogus admin locking everything up. Just creating the shortcut for the VRP wasn't too fun. Then right before the bogus account could fully load on a normal start up afterwards the VPC was able to remove it and get Windows back running somewhat normal again long enough to find out the damage was a bit more extensive then first realized.

Unfortunately if you run a search for removal instructions for this one the Win 7 Antispyware 2012 you end up being told you have to download some shareware version of some retail software. The VIPRE Rescue Program is strictly a free removal tool to give a try at seeing this one removed. Just beware that while you may all traces removed the damages done will depend on how this one was written.

Something to add in here! I just spotted this one on another thread regarding problems seen after malware was removed. This would be something to consider here as well. http://www.sevenforums.com/tutorials/19449-default-file-type-associations-restore.html
 
Last edited:

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer
Back
Top