Saturday, February 21, 2009

Updates on the Antivirus XP/Vista/2008/2009/360 malware **CRITICAL**

We had a tech doing research for us on the Antivirus XP/Vista/2008/2009/360 malware issue and critical updates were found! As we have told you before it literally takes control of the infected computer and begins redirecting you when you try to get online. Those redirects are becoming more dangerous as they perfect the "spoof pages" and try to dupe you into "purchasing" the malware and hence sending your credit card information to HACKERS.

We came across a very informational site which you can find at HERE. We are going to give you a brief run down on the most interesting things we found on that blog.....

FAKE BOSD (Blue Screen of Death)! This was seen by the blogger and it's interesting because this really begins to shed light on exactly how far the makers of this malware are willing to go. Here's a screenshot for you and if possible try to read what 's on the screen. It's not your typical BSOD.....




Fake Windows start up screen! This was particularly interesting because it was noted that this, along with the previously mention fake BSOD were seen after the computer began restarting itself without warning. Please be sure to read the fine print at the bottom of this screen.




Just as a reminder, if you see strange pop-ups, are being redirected to strange websites when you try to get online, or if your computer is running slow, freezing up or acting odd then you should shut it down and contact a professional! Our most recent client continued trying to use the infected computer and in the end the drive had to be reformatted because the infection was just too severe. There are free tools available online but if you don't have the ability to get online than it's pretty pointless.

If you are gung-ho and want to take a stab at getting rid of it yourself then these are what we recommend:

1. COMBOFIX - this kills it's system processes and allows you to begin using the rest of the software needed to remove it much more quickly. You may need to rename the file before you install it on the computer! You can get full instructions on how to use this HERE

2. Next we run MALWAREBYTES to continue the cleaning process.

3. Finally we run SUPERANTISPYWARE to complete the process.

There are some other tools which you may wish to try but we have had the greatest success with those three listed. We have read about Spybot Search and Destroy working but we have used that in the past and it didn't do as good a job as the SuperAntiSPyware did. You can also try Ad Aware, it has been suggested that you remove the FOLDER for the malware and then reboot your computer but becuase it tends to infect/alter registry entries, we can't say this will in fact work but it may be worth a try.

You can do this by first starting in safemode (hit F8 repeatedly upon restart) going to start --> RUN and then type in C:\Program Files\ and then press the OK button. When the folder appears, if it says These files are hidden, click on the Show the contents of this folder option. When the C:\Program Files\ folder opens, look through the list of folders and when you find the folder named XPAntivirus left-click on it once so it becomes highlighted. Then hit the Delete button on your keyboard and when it asks if you are you want to delete the folder, click on the Yes button with your mouse. When the folder is deleted, reboot your computer back to normal mode.

No comments:

Post a Comment