Whats the best virus scaner right now?

Chrome automatically updates flash on its own. It’s also fully sandboxed.

If mouse gestures worked better, I’d switch to chrome in a second flat.

Ug. Yes, the spell checker certainly can be described as shitty. For the world’s premier search engine company it’s just amazingly pathetic and sometimes just wrong.

Yes, for now at least. Don’t discount the auto update as a highly valuable feature. Google updates their browser constantly in a painless, almost invisible manner.

You don’t have to rely on Chrome for spell checking.

For those still getting infected, I’d suggest, beyond switching to Chrome, that you pick up Privoxyas well. It’s a free advertising and malicious IP-blocking local proxy. It filters all communications for your OS, so it’ll even help you with applications that embed IE.

UAC did. That was before I installed Winpatrol, which I did after last nights attack.

It was a virus because that is what MBAM found when I ran it in safe mode later.

My hero! Seems to be working well. It’s already better than Google’s and the integration seems to be spot on.

So it looks like something turned off the windows firewall and I can’t get it to start back up. Any ideas?

I’ve been using Comodo’s free firewall for a good year now, and it’s way better than Windows built in one anyway. Worth a shot.

Maybe you have the same virus as I do (did)? I had the “Vista Security 2012” malware - apparently a more recent version.
It did a shit-ton of damage to my machine.

Security Center service deleted:
http://forums.pcworld.co.nz/archive/index.php/t-116524.html
http://answers.microsoft.com/en-us/windows/forum/windows_7-security/windows-security-center-service-has-been-removed/47b55525-f0be-4434-95c3-265fbba64807
Firewall service deleted:

Now I’m trying to figure out why the hell explorer is missing all the New->File commands on my c:\drive except on my desktop. Permissions fucked up?

Oh - and it deleted my system restore points, so its either rebuild my machine without a good backup, or clean it up and hope for the best. I’m going to clean it up, and hope I can skip the week of rebuilding I don’t have time to do.

Man that sucks. Best of luck with all that. Having had to clean many a machine for family, I hate malware with a passion.

Most often I made them periodically back up important crap and just nuked everything, as the alternative could be such a pain in the ass.

OK - an hour later, I think my machine is fixed up. I’ve updated my past post with the helpful links. Apparently the root of c:\ being locked down is a feature that I must have disabled in the past somehow - whoops. Now I guess its working (as it should, as opposed to how it was). Other folders behave as expected.

What a pain in the ass. I should install a VM just for browsing the internet. WTF isn’t that standard now?

Yeah, that was the one. I got the Security Center working by downloading the replacement registry but hadn’t figured out how to get the firewall up. Thanks for the links, I’ll give that a try.

Edit: Still not having any luck getting the firewall back up. I’m running Vista while the two links are for WinXP and Win7. I tired the WinXP stuff but it didn’t see to work. For some reason I get an error when I try and import the new registry file. What specifically worked for you?

For the firewall I made a .reg file with this inside - then imported it. After reboot it worked again:
Stuff inside

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc]
“DisplayName”="@%SystemRoot%\system32\FirewallAPI.dll,-23090"
“Group”=“NetworkProvider”
“ImagePath”=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,
00,65,00,4e,00,6f,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,00,00
“Description”="@%SystemRoot%\system32\FirewallAPI.dll,-23091"
“ObjectName”=“NT Authority\LocalService”
“ErrorControl”=dword:00000001
“Start”=dword:00000002
“Type”=dword:00000020
“DependOnService”=hex(7):6d,00,70,00,73,00,64,00,72,00,76,00,00,00,62,00,66,00,
65,00,00,00,00,00
“ServiceSidType”=dword:00000003
“RequiredPrivileges”=hex(7):53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,
00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,
72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,75,
00,64,00,69,00,74,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,
00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,
00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,
53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,
00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,
65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,
6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
“FailureActions”=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,
00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters]
“ServiceDll”=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,
6d,00,70,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
“ServiceDllUnloadOnStop”=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap]
“Collection”=hex:87,00,01,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters\PortKeywords\Teredo]
“Collection”=hex:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Security]
“Security”=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,30,00,00,00,02,
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,
00,00,02,00,84,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,
00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,28,00,15,00,
00,00,01,06,00,00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,
0e,a7,8b,eb,ca,7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,
00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc\Enum]
“0”=“Root\LEGACY_MPSSVC\0000”
“Count”=dword:00000001
“NextInstance”=dword:00000001

Another vote for Comodo for an all-in-one solution. Based on the description here, it sounds like Comodo’s Defense+ is ‘winpatrol’ plus sandboxie, plus it has a firewall and anti-virus. I have no issues with performance, is configurable to be as loud or quiet as needed (ie., security pop-ups), can do ‘cloud scanning’ if you desire, etc. I also run Malwarebytes on-demand just as a precaution, but Comodo does the bulk of things.

EDIT: The one place it sorta falls down though is in a multi-user situation. I remote into my desktop from a laptop while the kids are playing on it, and Comodo will sometimes get confused about where to send security popups…

What did you name the file? I tried to create the .reg file per the earlier link, via Notepad, and I get an error when I try and import it, so a step by step on what worked for you would be helpful.

Edit: I took the situation to Bleepingcomputer.com’s boards and the guy that responded to my thread suggested the Comodo route was probably the easiest given that several of the Windows firewall .reg entries are missing. It’d be nice if MS offered the ability to reinstall that specific part of the OS.

Just named it file.reg - double clicked it - and it got imported right in. That easy. It is kinda silly that you can’t reinstall/repair OS components through their website in this day and age.

I got the registry file to import but still no go on firewall starting up. Still gives me the same error messages. Guess its Comodo time.

Kaspersky makes a nice boot from USB/cd and then run cut down Linux with scanner for those situations.

Yeah, my system is probably fucked beyond repair from this latest one. Its stable and cleaned, but I can’t get windows firewall to work anymore and it turns out windows update is busted as well. Luckily you can manually update MSE, but if you can do that with Windows in general I haven’t figured it out. I’m going through tech support with MS right now on the update issues, but don’t have a lot of confidence. Time to start transferring must keep stuff off in preparation for a complete nuking, even though I hate doing them. Almost makes me want to start over with a new harddrive and use this one as a second drive (and given the age of this harddrive is over 3 years, that might be a smart move anyway).

Thank you for posting this. I got hit by that same malware yesterday and was getting ready to prepare for a complete reinstall until I found this post. Sorry, but no more ads for me. I’m blocking them from here on out. I’ve been hit with this kind of crap twice in two years now. I don’t visit porn sites, torrent sites, or anything shady at all. I suspect I acquired the damn thing here, SA, or ZAM.

Thank you! I got hit by the same shitty malware and was about to prepare for a reinstall until I saw your post. Worked like a charm, Windows firewall and security center are back!