Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Fake Windows Antivirus 2012


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Fake Windows Antivirus 2012
Reply
 
Thread Tools
Old 27-12-2011, 08:05   #1
Milambar
cf.geek
 
Join Date: Jan 2008
Posts: 880
Milambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation eraMilambar has entered a golden reputation era
Fake Windows Antivirus 2012

4 of my friends, all with current antivirus software, and all with it completely up to date have gotten infected with this crudware.

It pretends to be antivirus software, but is infect, the actual virus.

All the usual fix methods failed, malwarebytes did not detect it, Im guessing its so new in the wild, the antivirus companies havent analyzed enough of them yet, to come up with defitions and a cure.

In each case, they tell me they got infected by "something on facebook".

So, people beware.
__________________
Algebra is great.

For a food-dish, of radius Z, and thickness A, you can say it is PI*Z*Z*A
Milambar is offline   Reply With Quote
Advertisement
Old 27-12-2011, 08:18   #2
Dai
Old dog, New tricks
 
Dai's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 64
Services: 50Mb, TV & Phone
Posts: 3,644
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Fake Windows Antivirus 2012

Thanks for the warning. I'll have to try and find out about this before my clients start reporting problems.
__________________
-= David =-

Under socialism ideology always trumps rationality.
Dai is offline   Reply With Quote
Old 27-12-2011, 08:25   #3
Peter_
Permanently Banned
 
Join Date: Jan 2009
Location: In a world of no buffering!!
Services: Samsung V+ XL TV XL Phone 30Mb Superhub Samsung Galaxy 3 32GB sd card In a world of no buffering!
Posts: 20,915
Peter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered stars
Peter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered stars
Re: Fake Windows Antivirus 2012

That keeps returning in various guises and seems in the main to be from clicking links in Facebook.
Peter_ is offline   Reply With Quote
Old 27-12-2011, 15:19   #4
LSainsbury
cf.mega poster
 
Join Date: Sep 2003
Location: Near Hungerford, West Berkshire
Services: TV: Sky HD, Landline: BT, Mobile: Orange, Internet: Quite Slow!
Posts: 6,580
LSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronze
LSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronzeLSainsbury is cast in bronze
Re: Fake Windows Antivirus 2012

Got some screenshots of this new malware / virus?
__________________
Cheers,
Lee


Please take a look at my photography site and leave me some feedback.
LSainsbury is offline   Reply With Quote
Old 27-12-2011, 17:21   #5
bw41101
Sigh...................!
 
bw41101's Avatar
 
Join Date: Mar 2007
Location: Blackpool
Services: Broadband XL TV XL Phone - A device with buttons that makes a funny noise when it rings!
Posts: 923
bw41101 has a bronzed appealbw41101 has a bronzed appeal
bw41101 has a bronzed appealbw41101 has a bronzed appealbw41101 has a bronzed appealbw41101 has a bronzed appealbw41101 has a bronzed appealbw41101 has a bronzed appealbw41101 has a bronzed appeal
Re: Fake Windows Antivirus 2012

Sounds like it could be the old Windows Antivirus trojan that's manifested itself on the particular PC. If you get any of the following that come up on your screen, I.e.:

"Internet attack attempt detected:
Somebody is trying to attack your PC:
This can result in loss of your personal information and infection other computers connected to your network."

"Warning: Infection is Detected
Windows has found spyware infection on your computer!
Click here to update your Windows antivirus software"

"svchost.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
If you are in the middle of something, the information you were working on might be lost."

"Security Warning
Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer.
Click here to clean your PC immediately."


If a dialogue box comes up with the above (or something similar) DON'T click on anything - not even the box's cancel button or the [X] in the corner. If you do you will activate an executable and infect your machine.

If the above happens, do a Ctrl+Alt+Delete (using the Windows task manager) and shut down your browser immediately. After this do a scan and (if you're lucky) you'll have caught it before any damage is done.

I got infected with this and the first I knew about it was when my desktop went black and every time I clicked on an icon I was told "access denied" basically I couldn't run anything. I did finally get rid of the problem manually but the hassle involved was significant and very time consuming indeed.

There's more information of the net regarding this along with the fixes for those unlucky enough to get infected.

Be vigilant!

Si thee
__________________
Nil Internet Explorer is a crock of hits (anag)
DISCLAIMER: If you find a posting from me to be in any way offensive or inappropriate, just ignore it. If you can't, then complain to me & I will be only too happy to advise....
bw41101 is offline   Reply With Quote
Old 27-12-2011, 17:58   #6
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 44
Posts: 17,512
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Fake Windows Antivirus 2012

The problem with clickware is that few AV programs will ever catch them as your click bypasses a lot of the security. Get a decent pop-up blocker as that will prevent it a lot more than an AV program
Kymmy is offline   Reply With Quote
Old 27-12-2011, 20:43   #7
Dai
Old dog, New tricks
 
Dai's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 64
Services: 50Mb, TV & Phone
Posts: 3,644
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Fake Windows Antivirus 2012

Some more info and removal tips here:

http://www.bleepingcomputer.com/viru...tispyware-2012

Ooh, even nastier:

"There have been reports of this infection being bundled with the TDSS rootkit infection"
__________________
-= David =-

Under socialism ideology always trumps rationality.

Last edited by Dai; 27-12-2011 at 20:46.
Dai is offline   Reply With Quote
Old 30-12-2011, 21:30   #8
Matth
cf.mega poster
 
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,071
Matth has reached the bronze age
Matth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze age
Re: Fake Windows Antivirus 2012

By no means new, yet there seem to be many accounts of it breezing past current antivirus - maybe there's just no defeating the most determined users, who will ok past all warnings and turn off their antivirus no matter how much you berate them.

One other thing, the friend who I had to clean this up for, was back on Vista no SP, wonder if missing updates are a factor.

Last edited by Matth; 30-12-2011 at 21:33.
Matth is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT. The time now is 05:06.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

(server6.cableforum.co.uk)

SEO by vBSEO 3.3.2