1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Possible PCHealth Virus - Defender.exe

Discussion in 'Malware and Virus Removal Archive' started by Genblue, 2011/04/15.

  1. 2011/04/15
    Genblue

    Genblue Inactive Thread Starter

    Joined:
    2011/04/15
    Messages:
    3
    Likes Received:
    0
    [Resolved] Possible PCHealth Virus - Defender.exe

    Yesterday my wife noticed a bunch of anti-virus screens pop up, none of which were the original AVG program that we were running.

    When I got home I tried to kill the process but it wouldn't allow me to access the task manager.

    I turned off the restore point while in safe mode and noticed in the start-up files a direct link to f:\windows\PCHealth. After some Googling, it looked to be the PCHealth virus. In safe mode, I deleted the directory and removed all of the references to PChealth in the Registry.

    Upon a full reboot the same problem persisted.

    I downloaded Malwarebytes and ran it. It found about 9 files, which I removed. Did a full reboot and the same problem persisted. This time I noticed that it referenced a W32blaster.worm name so I downloaded BlasterFix but that didn't find anything.

    I tried to ensure that the Windows Firewall is turned on but it wouldn't let me do that in safe mode. I tried to install the recommended Avira program but that won't run in safe mode either.

    Any help would be appreciated. Thanks in advance.
     
    Last edited: 2011/04/16
  2. 2011/04/15
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2011/04/15
    Genblue

    Genblue Inactive Thread Starter

    Joined:
    2011/04/15
    Messages:
    3
    Likes Received:
    0
    Thanks.. Attempted to follow the steps but couldn't check the status of the firewall, couldn't load Avira so I wasn't sure if I should just continue or not?
     
  5. 2011/04/15
    Genblue

    Genblue Inactive Thread Starter

    Joined:
    2011/04/15
    Messages:
    3
    Likes Received:
    0
    After further searching, the root virus was call the defender.exe.

    The file was in X:\Documents and Settings\[User Name]\Application Data

    The trick is that the folder is hidden.

    You need to change the folder attribute to remove the Hidden setting.
    I ended up using DOS to manually change the attribute.

    Once I changed the folder attribute and deleted the "defender.exe" file I was able to do a full reboot.

    I'm now running Malwarebytes and updating the antivirus program to make sure everything else is Ok.

    Thanks.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.