Vista Defender 2013 virus- Please help!

Status
Not open for further replies.

Sav22

New Member
Thread author
Oct 25, 2012
5
I have the Vista Defender 2013 virus and can't get onto the internet to download the RKill and other programs needed in order to handle the problem.

I tried to download the program "RKill" from the computer I am using now, transferred this onto a thumb drive, put this on my laptop, double clicked on the icon and the Vista Defender window popped up again and wouldn't allow me to get onto the internet.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Hi and welcome to the malwaretips.com forums!

I'm Kuttus and I am going to try to assist you with your problem. Please take note of the below:
  • I will start working on your malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.


Before we start:
Please be aware that removing malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.
<hr />

Please oepn My Computer
Please select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
After this please press the Apply button and then the OK


Now you need to open the Folder C:\Users\{Your User Name}\AppData\Local

Inside that folder you will be able to see one 3 character .EXE file..

Eg : jir.exe , fry.exe etc

Rename that folder with a name 1.exe.old and restart the computer... Now you will not get any pop ups... But you will not be able to open any .exe files.. You will be getting Open with if you are trying to open any application. No need to worry. Follow the Step-1.

If you are not able to download it on the infected computer download it on your other computer and Transfer it to the infected one....

STEP 1: Repair your Windows Registry from this infection malicious changes.

This infection has changed your Windows registry settings so that when you try to run a executable file (ending with .exe ) , it will instead launch the infection rather than the desired program.

  1. Download the registryfix.reg file to fix the malicious registry changes from System Progressive Protection.
    REGISTRYFIX.REG DOWNLOAD LINK (This link will automatically download the registry fix called registryfix.reg)
  2. Double-click on registryfix.reg file to run it. Click “Yes” for Registry Editor prompt window,then click OK.
<hr />

STEP 2: Run a scan with OTL by OldTimer
<ol><li>Download the OTL utility using the below link :
<><a title="External link" href="http://oldtimer.geekstogo.com/OTL.exe" rel="nofollow external">OTL DOWNLOAD LINK</a> <em>(This link will automatically download OTL on your computer)</em></></li>
<li>Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
<img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL-logo.png" alt="" title="OTL-logo" width="106" height="118" class="alignnone size-full wp-image-3946" /></li>
<li>When the window appears, <>underneath Output</> at the top change it to <>Minimal Output</>.</li>
<li>Check the boxes beside <>LOP Check</> and <>Purity Check</>.</li>
<li>Click the<> Run Scan</> button.
<img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL.png" alt="" title="OTL" width="658" height="584" class="alignnone size-full wp-image-3945" /></li>
<li>When the scan completes, it will open two notepad windows. <>OTL.Txt</> and <>Extras.Txt</>. These are saved in the same location as OTL.
<>Please post this 2 logs in your first reply.</>.</li></ol>
<em>Note: If OTL.exe will not run, it may be blocked by malware. Try these alternate versions: <a title="External link" href="http://www.itxassociates.com/OT-Tools/OTL.scr" rel="nofollow external">OTL.scr</a>, or <a title="External link" href="http://oldtimer.geekstogo.com/OTL.com" rel="nofollow external">OTL.com</a>.</em>

<hr />

STEP 3: Run a HitmanPro scan
<ol>
<li><>Download the latest official version of HitmanPro</>.
<a href="http://www.surfright.nl/en/hitmanpro/" rel="nofollow" target="_blank"> <>HITMANPRO DOWNLOAD LINK</></a> <em>(This link will open a download page in a new window from where you can download HitmanPro)</em></li>
<li>Start HitmanPro by <>double clicking on the previously downloaded file.</> and then following the prompts.
<img src="http://malwaretips.com/images/removalguide/hpro4.png" alt="[Image: hitmanproscan4.png]" border="0" /></li>
<li>Once the scan is complete, a screen displaying all the malicious files that the program found will be shown as seen in the image below.After reviewing each malicious object click <>Next</> .
<img src="http://malwaretips.com/blogs/wp-content/uploads/2012/02/rsz_hpro5.png" alt="[Image: hitmanproscan5.png]" border="0" /></li>
<li>Click <>Activate free license</> to start the free 30 days trial and remove the malicious files.
<img src="http://malwaretips.com/images/removalguide/hpro6.png" alt="[Image: hitmanproscan6.png]" border="0" /></li>
<li>HitmanPro will now start removing the infected objects, and in some instances, may suggest a reboot in order to completely remove the malware from your system. In this scenario, always confirm the reboot action to be on the safe side.
</ol>
Add to your next reply, any log that HitmanPro might generate.
<hr />

What's next?

Add the following logs to your next post (You can find here details on how to use the Attachment System):
1. OTL Log
2. Hitman Pro log
3. Let me know if you had any problems with the above instructions and also <>let me know how things are running now!</>


<hr />
 
Last edited by a moderator:

Sav22

New Member
Thread author
Oct 25, 2012
5
Wow. Okay thank you very much. I started this but I don't have "Display the contents of system folders" in my computer under "view". Please advise.
 

Fiery

Level 1
Jan 11, 2011
2,007
Sav22 said:
Wow. Okay thank you very much. I started this but I don't have "Display the contents of system folders" in my computer under "view". Please advise.

I believe the "Display the content of system folders" is in Windows XP only. In Windows Vista,

Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.

Should net the same result. Try and see if that works.
 

Sav22

New Member
Thread author
Oct 25, 2012
5
Thank you and I was able to find that. Now I am looking for the .exe file in the Local folder and do not see anything. I renamed the Local folder anyways and it just made another copy of the Local folder but the new folder (1.exe.old) doesn't have all the files that the Local folder has.

Please advise. Standing by.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Sav22 said:
Thank you and I was able to find that. Now I am looking for the .exe file in the Local folder and do not see anything. I renamed the Local folder anyways and it just made another copy of the Local folder but the new folder (1.exe.old) doesn't have all the files that the Local folder has.

Please advise. Standing by.



Hi,

No need to Rename the LocalFolder. That may unstable your computer... If you are not able to find the .exe file inside the Local Folder go with the Step -1.

Download the RegFix file from this link.... RegFix

Please make sure you undo all the changes you have done with the Local Folder.....
 

Sav22

New Member
Thread author
Oct 25, 2012
5
Thank you very much. I did as directed above and the virus seems to be gone.

However, I am getting a message that reads:

"Check you computer security. There are multiple security problems with your computer. Click this notification to fix these problem."

Is this the same virus or another one or a real notification?
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
That one seems to be real one.... No need to worry we can if it.... Please run the above tools and send me the logs......



What's next?

Add the following logs to your next post (You can find here details on how to use the Attachment System):
1. OTL Log
2. Hitman Pro log
3. Let me know if you had any problems with the above instructions and also <>let me know how things are running now!</>


<hr />




Sav22 said:
Thank you very much. I did as directed above and the virus seems to be gone.

However, I am getting a message that reads:

"Check you computer security. There are multiple security problems with your computer. Click this notification to fix these problem."

Is this the same virus or another one or a real notification?
 
Last edited by a moderator:

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Great to hear that.. Is there anything else that we can assist you with?


Do you want me to check for presence of any other possible infection's on the computer ?



What's next?

  1. Bulild up your malware defenses by starting a new thread in Security Configuration Wizard forum.
  2. Learn how to avoid malware by reading this article <a href="http://malwaretips.com/blogs/how-to-easily-avoid-pc-infections/">How to easily avoid malware</a>
  3. Be an active member in the MalwareTips community! :)
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Sav22 said:
Everything is all back to normal now! Thank you!!!

This thread is now closed.​
Reason:&nbsp;<span style="color: #ff0000;">Resolved</span>

<span style="color: #ff0000;"><>The procedures contained in this thread are for this user and this user only.&nbsp;&nbsp;Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair.&nbsp;&nbsp;</></span>

<span style="color: #ff0000;"><>DO NOT use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist.</></span>

All members requesting Malware Removal Assistance are required to follow all procedures in the thread
 
Last edited by a moderator:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top