Click on screenshot to zoom
Danger level 10
Type: Adware
Common infection symptoms:
  • Installs itself without permissions
  • Connects to the internet without permission
  • Shows commercial adverts
  • Slow internet connection
  • Annoying Pop-up's
  • Slow Computer

Windows Security Virus

Windows Security Virus is the term used to refer to a new computer infection that blocks access to various websites, mainly Russian websites, and provides computer users with a fake system scanner. The interface of the scanner resembles the Windows operating system, which may encourage gullible computer users to fall for the trick. The fake scanner called Windows Security is displayed in several ways. For example, the Windows Security Virus can show its interface once you open a browser. The infection also edits the Windows hosts file, which means that it adds a list of websites that cannot be accessed. When you enter the URL of a website that is on the list, you are provided with the Windows Security scanner.

Our analysis of the infection has showed that the hosts file contains over 700 entries, which include Facebook, Instagram, Yandex, and many other Russian websites.

This host file is modified by an executable file named w1ndows_b456, the name of which may vary on different computers. More specifically, it contains some other randomly selected characters.

The infection starts at every Windows startup, and we recommend that you take some preventative measures as soon as you can.

According to the Windows Security Virus, your computer is infected with various infections. Without a doubt, you are offered a chance to have those infections removed for a particular free, which is $4.75 USD. Even though the sum is relatively small compared to the sums required by other rogue anti-virus programs, we recommend that you take action to remove the so-called Windows Security Virus from the computer. The fact that your Internet browsers have been affected by a piece of malware implies that your computer is not protected in the way it should be; hence, a reputable security program should be installed as soon as possible.

As regards the removal of the Windows Security Virus, we strongly recommend that you implement SpyHunter, which a powerful security tool that can terminate the infection in no time. It fixes the hosts file and safeguards the system against multiple computer infections, including other fake anti-virus programs, browser hijackers, adware programs, rootkits, etc.

Below you will find our step-by-step instructions that should help you access the hosts file and remove the executable file of the threat. If you have any questions regarding the removal of this threat, feel free to leave a comment below.

How to remove Windows Security Virus

  1. Click Start.
  2. Select All Program and click Accessories.
  3. Right-click Notepad and select Run as administrator.
  4. Open the Hosts file (c:\windows\system32\drivers\etc) and delete the unnecessary entries. Make sure that the text in the file ends with localhost or ::1 localhost.

Remove the executable file

  1. Restart the computer.
  2. Wait for the BIOS screen to appear and start tapping the F8 key.
  3. Select Safe Mode and hit Enter.
  4. Open the AppData directory and remove the malicious file.
Download Spyware Removal Tool to Remove* Windows Security Virus
  • Quick & tested solution for Windows Security Virus removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.