A new years virus, yay

Rathion

Famous
Joined
Jul 22, 2009
Messages
442
Was browsing on steam and the moment midnight hit BAM I had 3-4 pop ups for "Win 7 Antispyware 2012" or something of the sort. I knew it wasn't legit and it seems to have knocked my Microsoft security essentials out within moments. I have figured out the tec.exe in the task manager are the programs disguised as some windows presentation process. I am running a brand new scan for spybot but I can not install any .exes due to the virus. Spybot is all I have on my computer besides security essentials and it won't even launch.

Does anyone have any tips or help for me? I would rather not uninstall. I believe I contracted the virus by some security risks I took when fixing my cousins computer that was loaded with all sorts of viruses.
 
This website has helped me remove these dreaded viruses every time...

Here's a link to the one you mentioned, follow everything exactly and you should be good to go.

Please post back if you have any further questions or if you made any progress.
 
I had it also, the only way I could get rid of it was a system restore.

I tried using malwarebytes too, but it would temporarily remove it and would come back later in the day.
 
After further research I just decided it best to use a backup I made a week ago. Haven't seen any issues so I think I got rid of the sucker. The virus basically took out everything but spybot and made my computer useless. That thing is nasty.
 
Me and my brother get these all the time while just searching the internet. I just system restore. Maybe I need a new anti-virus, Microsoft security essentials must not be doing the trick.
 
Note of caution: If by SpyBot you mean "SpyBot search and destroy", this program gave my old computer a virus...No joke. Did all the research n what not, and the file was from Spybot. :|
 
I find it extremely difficult that a reputable program like spybot would give me a virus.
 
Download these files if possible on another computer and throw them on a flash drive

Rkill.exe
http://www.bleepingcomputer.com/download/anti-virus/rkill

Combofix
http://www.bleepingcomputer.com/download/anti-virus/combofix

Malwarebytes
http://filehippo.com/download_malwarebytes_anti_malware/

Manual Update for Malwarebytes
http://forums.malwarebytes.org/index.php?showtopic=102093

I actually just had to remove this from my girlfriends mas computer

Reboot into safemode ( i used with networking but you dont have to) Run Rkill give it a few to run and what not.

Then install Malwarebytes if you have it installed uninstall reboot back into safemode and reinstall. Run the Manual update if your not using safemode with networking.

Run a full scan of Malware bytes

after scan and reboot, run combofix it takes a bit

Last thing i did was i had problems getting MSE to open so i uninstalled rebooted ran ccleaner and reinstalled mse and ran a full scan with that.

Computer was clean no issues.
 
First,

When you have a virus, DO NOT System Restore. This will duplicate the virus in a system restore folder.

Secondly, only use Combofix when asked to by a superior technician, failure to do so can cause lose of data and an inoperable pc. Combofix is an extremely powerful tool and should only be used as a last measure. It is not recommended that you use other tools when you plan to use Combofix, as Combofix will over ride any rules set by previous programs.
 
Last edited:
First,

When you have a virus, DO NOT System Restore. This will duplicate the virus in a system restore folder.
so what should I do, because I get his same virus and that is what I do. I just got it back again today while browsing again. The page just closes and the virus pops up. What should I do to delete the virus once and for all? Also I use microsoft security essentials, should I get a new anti-virus?
 
Well I have used combofix A LOT, never once had an issue even in use with rkill and everything else, as a matter of fact i just did the whole entire method i explained to him to do on a customers laptop about 2 hrs ago. That laptop is working 100% great and i have another happy customer.
 
I restored from a old backup and got it a few days afterwards. I'm scanning with every program I have.
 
I went back to the SAME backup and their is no hint of the program now with any programs I run. I guess one of the websites I visit is infecting me.
 
Same thing happened to me. Since I lurk my task manager too often, I know which programs are safe and which are not. Getting the task manager up was a pain.. The virus was blocking all executables aswell as task manager (though a certain delay was present). I managed to find the name of the virus .exe because of its obvious randomized name and then proceeded to reboot into safe mode and delete the file after searching for it.

Problem fixed!

Though this might be a different virus..

Fixed the same kind of thing on a friends computer twice too.
 
Last edited:
In general, running FixNCR.reg, RKill, and MalwareBytes (fully updated, of course) will take care of a LOT of viruses. FixNCR.reg and RKill can be found at http://www.bleepingcomputer.com. FixNCR.reg needs to be run first to undo the changes a lot of viruses make to file associations, followed by RKill to stop all malicious processes. After both of those have run their course, MalwareBytes will usually open without trouble.

As for staying away from dangerous sites, I'd recommend installing the WOT (Web of Trust) add-on for Firefox and Chrome. It tells you how dangerous the site you're currently on is, and also puts an indicator icon next to Google search results.

Disabling JavaScript for untrusted sites is a great strategy, too. The NoScript add-on for Firefox is great for managing JavaScript. Turning off JavaScript in Chrome puts an icon in the address bar that asks if you want to trust the site, but it's not as detailed as Firefox with NoScript.
 
I support Rkill and Malwarebytes. For what it's worth, I bought Malwarebytes and it updates daily.
 
As for staying away from dangerous sites, I'd recommend installing the WOT (Web of Trust) add-on for Firefox and Chrome. It tells you how dangerous the site you're currently on is, and also puts an indicator icon next to Google search results.
this is going to sound weird but I got the virus again today while searching the ego website with a few tabs open. But maybe its caus I just system restore when I get the virus so I dont actually kill it.
 

Latest posts

Back
Top