Anti Virs 2009
Results 1 to 10 of 10

Thread: Anti Virs 2009

  1. #1
    Registered User Zonie's Avatar
    Join Date
    Apr 2001
    Location
    Phoenix, Arizona
    Posts
    1,461

    Anti Virs 2009

    Was just wondering iif anyone has seen an increase in infections from this and other Trojans lately? In the last 5 days, I have been unindated with calls for problems with this.

  2. #2
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    Actually saw this on the increase a month or so ago. Its a nasty piece of work that's for sure.
    Safe mode and malwarebytes and spybot updated seem to do it,as well as kill the restore file
    Last edited by Ferrit; December 24th, 2008 at 02:11 PM.

  3. #3
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    I see so much of this and its variants that I wouldn't notice an increase unless infections increased about 100 times. Currently, my normal procedure is to start any malware removal by running 2 passes of ComboFix, followed by Spybot S&D, and Eset's online scan, or installing and running a trial version of NOD32 on the computer in place of the online scan.

  4. #4
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    The last 6 or 7 machines I got in this week with the fake antivirus derivatives also all had an interesting zlob rootkit.

  5. #5
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    That is correct. The infection rate has picked up. The likely culprit in my questioning of clients is it happened right after they clicked a microsoft update window / microsoft security window. It's a fake that looks very close to the real thing. There are other methods but the string of infections I've cured lately fit that M.O.. I suspect since it's the holidays the fake ups tracking mail that carries it is succeeding very well at the moment too.

  6. #6
    Registered User Guts3d's Avatar
    Join Date
    Jan 2003
    Location
    Pittsburgh U.S.A.
    Posts
    2,328
    Just had a lady call about this and ask me if I could fix her comp tonight, I reminded her it is Christmas Eve here and the earliest I can see it is Friday. ( Off work until January 5th! )

  7. #7
    Registered User
    Join Date
    Mar 2005
    Posts
    1,534
    It is now AV 2010. Same procedure apply to getting rid of this variant also. I have done probably 50 of these in the last 4 months.
    Last edited by Kodiak; December 27th, 2008 at 11:15 AM.

  8. #8
    Registered User Zonie's Avatar
    Join Date
    Apr 2001
    Location
    Phoenix, Arizona
    Posts
    1,461
    Haven't seen the AV2010 yet, but this other one has either mutated or brought something else with it. Several I have tried to clean in safe mode, I had to rename combfix, smith fraud and then even had malwarebytes and spyotbot not even run. In task manager it would show the process running but nada on the program. I have found going to google's spyware doctor usually cleans it up enough to get the rest of the tools running.

  9. #9
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    A few tips for you when in a situation where it won't let you open your tools for removing the infection. Check the startup folder and the run folder in the registry. Remove anything that has gibberish for a name or is even named antivirus200x or similarily named to whatever the infection claims to be. Secondly go to the program files folder and delete all gibberish folders (gibberish being folder names similar to aiwx3bxeb), folders named after the infection, and check for a folder named SAV if you don't have norton/symantec installed because this is a fake folder designed to keep you away from the infections files. Also go into the documents and settings and check each profiles hidden folders of application data, and the local settings\application data for any folders with gibberish names or even named similar to the infection. A final note change the home page to the web page or you may stand to reinfect yourself. Once this is done do your scans/clean ups if those still fail because the infection is stil running reboot back into safe mode then do your clean up.
    One Script to rule them all.
    One Script to find them.
    One Script to bring them all,
    and clean up after itself.

  10. #10
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    The current crop of Smitfraud variants has been a pretty hot topic lately. Just a Geoscomp says, Zlob is a frequent companion, and Virtumondo remains one as well. I've seen fewer infections of this from porn sites recently, and a lot more from bogus ecards. 'Tis the season, I guess.

    MS recently released new versions of their Malicious Software Removal Tool, that have enhancements specifically targeting these infections.

Similar Threads

  1. What do you suggest for an anti Virus Program?
    By pcgal in forum Spyware & Antivirus - Security
    Replies: 10
    Last Post: September 2nd, 2005, 08:05 PM
  2. Replies: 0
    Last Post: July 14th, 2005, 10:16 AM
  3. Anti Anti Pop ups
    By TechZ in forum Other Software Applications
    Replies: 1
    Last Post: April 30th, 2004, 12:22 PM
  4. [RESOLVED] Anti Virus created stacking problem
    By robfam in forum Spyware & Antivirus - Security
    Replies: 5
    Last Post: June 8th, 2002, 01:03 AM
  5. panda anti virus
    By edhunter in forum Spyware & Antivirus - Security
    Replies: 2
    Last Post: May 30th, 2001, 08:40 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •