Whats the best way to remove "Win 7 Security 2012" virus?

Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: 009to090 On: Fri Dec 16, 2011 9:44 pm

Current virus definitions up to date. Yet still, my Wife's PC just got the "Win 7 Security 2012 virus/malware. I tried booting up in safe mode to install a 'cleaner'. The virus interupted it. I tried Systen Restore. It failed with an error.

Anyone know how to get rid of it?
User avatar
009to090
State of North Carolina Moderator
 
Posts: 4988
Joined: Fri Jan 30, 2009 11:02 am
Location: Warrenton, NC
Stove/Furnace Make: Harman DVC500 x 2
Stove/Furnace Model: EFM 520 HighBoy


Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: SMITTY On: Fri Dec 16, 2011 9:47 pm

Well, in all my electronic frustration over the years, this seems to fix every problem.

Hell, it fixed my printer right up nicely. ;)

Image

Image
User avatar
SMITTY
Member
 
Posts: 9064
Joined: Sun Dec 11, 2005 1:43 pm
Location: West-Central Mass
Stove/Furnace Make: Harman
Stove/Furnace Model: Mark III

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: freetown fred On: Fri Dec 16, 2011 10:26 pm

Any questions Chris???
User avatar
freetown fred
Member
 
Posts: 10132
Joined: Thu Dec 31, 2009 1:33 pm
Location: Freetown,NY 13803
Stove/Furnace Make: Hitzer
Stove/Furnace Model: 50-93

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: 009to090 On: Fri Dec 16, 2011 10:35 pm

freetown fred wrote:Any questions Chris???

Nope, that was my first choice.... The wifey put a stop to that, though :D

I'm going thru the online procedures to remove it now. Seems like it gets right by all antivirus software, even if its been updated.....
User avatar
009to090
State of North Carolina Moderator
 
Posts: 4988
Joined: Fri Jan 30, 2009 11:02 am
Location: Warrenton, NC
Stove/Furnace Make: Harman DVC500 x 2
Stove/Furnace Model: EFM 520 HighBoy

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: 009to090 On: Fri Dec 16, 2011 10:56 pm

Well, it looks like the System Restore did work, even though it ended with an error. After a restart, I was able to download a new Virus definition file for my antivirus software, and it is busily doing a full scan right now.
:flex:
User avatar
009to090
State of North Carolina Moderator
 
Posts: 4988
Joined: Fri Jan 30, 2009 11:02 am
Location: Warrenton, NC
Stove/Furnace Make: Harman DVC500 x 2
Stove/Furnace Model: EFM 520 HighBoy

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: freetown fred On: Fri Dec 16, 2011 11:17 pm

Yep, that system restore has saved my ass more then once. Outstanding my friend. :)
User avatar
freetown fred
Member
 
Posts: 10132
Joined: Thu Dec 31, 2009 1:33 pm
Location: Freetown,NY 13803
Stove/Furnace Make: Hitzer
Stove/Furnace Model: 50-93

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: lsayre On: Fri Dec 16, 2011 11:28 pm

Install Linux. It laughs at Windows viruses.
User avatar
lsayre
Member
 
Posts: 4035
Joined: Wed Nov 23, 2005 10:17 pm
Location: N/E Ohio, near Wadsworth
Stove/Furnace Make: AHS S130 Coal Gun

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: coalvet On: Sat Dec 17, 2011 9:04 am

This has worked for me in the past and it's free! Just download it, install, run and then uninstall after the scan!

http://support.kaspersky.com/viruses/av ... 11?level=2

Rich
User avatar
coalvet
Member
 
Posts: 168
Joined: Tue Feb 27, 2007 1:48 pm
Location: Rhode Island
Stove/Furnace Make: Crane
Stove/Furnace Model: Model 404

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: ValterBorges On: Sat Dec 17, 2011 11:52 am

009to090 wrote:Current virus definitions up to date. Yet still, my Wife's PC just got the "Win 7 Security 2012 virus/malware. I tried booting up in safe mode to install a 'cleaner'. The virus interupted it. I tried Systen Restore. It failed with an error.

Anyone know how to get rid of it?



Get the wife and kids an ipad for surfing.

Get a technet subscription from MS and find the latest drivers for your Rig.
Many times system restores install all kinds of custom junk programs which may have rogue ads which lead you to sites with spy/malware.

Install a fresh os, drivers, win 7 should find most mobo components, and apps.
Get all the latest updates, patches.

Make your own recovery Dvds
User avatar
ValterBorges
Member
 
Posts: 569
Joined: Mon Sep 05, 2011 10:12 pm
Location: Berlin, CT
Stove/Furnace Make: AHS
Stove/Furnace Model: S260

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: ValterBorges On: Sat Dec 17, 2011 11:56 am

Then make sure you backup your critical files to offsite storage, rewritable dvd, or nas device with raid.

Every year make it a habbit of restoring the image updating the image with latest patches, software.

Think of it like shutting down the boiler, and getting it cleaned and oiled for another season.
User avatar
ValterBorges
Member
 
Posts: 569
Joined: Mon Sep 05, 2011 10:12 pm
Location: Berlin, CT
Stove/Furnace Make: AHS
Stove/Furnace Model: S260

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: mozz On: Sat Dec 17, 2011 3:34 pm

It is a pain in the *ss to get rid of, it has a root kit so go get this first.
Kapersky TDSS Killer 2.6.23.0. It is free and so are any updates, it doesn't run in the background or anything like that, no memory usage. You have to open the program to make it run so get in the habit of running it every few days. Next, go to http://www.malwarebytes.org/ get the free download, it only runs 30 days but it is the only thing that will find the infected files, Windows Security Essentials does not find the problem and doing a restore does no good because the problem is embedded in the rootkit virus. Malwarebytes will still work after 30 days and go get updates but it is limited. I paid the $24.99 and bought the full version because i like the way it finds stuff that Windows and others do not find. Believe me, i had problems with this for a while, if you open task manager and see a exe file with 3 letters, that is your virus running, every time you open a program, it also opens, it looks like a real Windows security warning but it is not, be warned, really a pain in the butt.
User avatar
mozz
Member
 
Posts: 825
Joined: Mon Sep 17, 2007 5:27 pm
Location: Wayne county PA.
Stove/Furnace Make: Axeman Anderson
Stove/Furnace Model: 1982 AA-130 Steam

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: 009to090 On: Sat Dec 17, 2011 8:37 pm

mozz wrote:It is a pain in the *ss to get rid of, it has a root kit so go get this first.
Kapersky TDSS Killer 2.6.23.0. It is free and so are any updates, it doesn't run in the background or anything like that, no memory usage. You have to open the program to make it run so get in the habit of running it every few days. Next, go to http://www.malwarebytes.org/ get the free download, it only runs 30 days but it is the only thing that will find the infected files, Windows Security Essentials does not find the problem and doing a restore does no good because the problem is embedded in the rootkit virus. Malwarebytes will still work after 30 days and go get updates but it is limited. I paid the $24.99 and bought the full version because i like the way it finds stuff that Windows and others do not find. Believe me, i had problems with this for a while, if you open task manager and see a exe file with 3 letters, that is your virus running, every time you open a program, it also opens, it looks like a real Windows security warning but it is not, be warned, really a pain in the butt.

Thanks Mozz, yes, I ran the Malwarebytes after the System Restore. Nothing found. Also ran the TDSS Killer with same results. Seems like the System Restore wiped out all traces of it.
User avatar
009to090
State of North Carolina Moderator
 
Posts: 4988
Joined: Fri Jan 30, 2009 11:02 am
Location: Warrenton, NC
Stove/Furnace Make: Harman DVC500 x 2
Stove/Furnace Model: EFM 520 HighBoy

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: mozz On: Sat Dec 17, 2011 8:45 pm

Just be careful. first time i had the virus, it came back. I don't trust system restore or Microsoft security essentials. Run Malwarebytes every few days and do a full scan instead of quick scan. Better safe then sorry. I think mine was coming up under task manager as ofv.exe.
Associated Malware Groups
The unsafe files using this name are associated with the malware groups:

Cloaked Malware
Malicious Software

File Behavior

OFV.EXE has been seen to perform the following behavior:

Writes to another Process's Virtual Memory (Process Hijacking)
Executes a Process
Registers a Dynamic Link Library File
This process creates other processes on disk
The Process is packed and/or encrypted using a software packing process

OFV.EXE has been the subject of the following behavior:

Executed as a Process
Created as a process on disk
Has code inserted into its Virtual Memory space by other programs
Terminated as a Process
Registered as a Dynamic Link Library File

Country Of Origin

The filename OFV.EXE was first seen on Feb 6 2010 in the following geographical regions of the Webroot community:

Philippines on Feb 6 2010
New Zealand on Apr 30 2010
The United Kingdom on Apr 30 2010
Mexico on Oct 6 2010
The United States on Jan 13 2011

File Name Aliases

OFV.EXE can also use the following file names:

KGK.EXE
KGN.EXE

Filesizes

The following file size has been seen:

161,792 bytes
359,424 bytes
387,072 bytes
289,792 bytes
321,024 bytes
136,704 bytes
211,968 bytes

File Type

The filename OFV.EXE refers to many versions of an executable program.
User avatar
mozz
Member
 
Posts: 825
Joined: Mon Sep 17, 2007 5:27 pm
Location: Wayne county PA.
Stove/Furnace Make: Axeman Anderson
Stove/Furnace Model: 1982 AA-130 Steam

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: Wiz On: Sun Dec 18, 2011 8:24 pm

Worst case, you can reformat pc to take it to original state. It's a good habit to reformat any pc every 2 yrs.
User avatar
Wiz
Member
 
Posts: 453
Joined: Sun Nov 27, 2011 9:45 pm
Location: Tannersville Pa
Stove/Furnace Make: KeyStoker
Stove/Furnace Model: Ka-6 Boiler

Re: Whats the best way to remove "Win 7 Security 2012" virus?

PostBy: SMITTY On: Sun Dec 18, 2011 8:47 pm

By reformatting do you mean wiping out the whole disc & reloading the OS? I've always heard of doing this but sounds like a MAJOR pain in the ass. Every single computer I have had probably needed this.
User avatar
SMITTY
Member
 
Posts: 9064
Joined: Sun Dec 11, 2005 1:43 pm
Location: West-Central Mass
Stove/Furnace Make: Harman
Stove/Furnace Model: Mark III


cron