Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

*PSA* Antivirus 2009 is one nasty piece of malware, but I kilt it!

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 12:47 AM
Original message
*PSA* Antivirus 2009 is one nasty piece of malware, but I kilt it!
My son swears he didn't download anything, yeah right:eyes:, but somehow his PC picked up "Antivirus 2009". This program disguises itself as a "Windows Security Center", complete with Windows icons. At first it's just supremely annoying, but when you try to get rid of it, hoo boy the claws come out! I finally learned that Malwarebytes spyware/malware program was the way to go, and when I tried to download it, AV2009 went nuts! It started it's rampage by blocking me from downloading, even to the point of going to it's own "blue screen of death". Then, after I did get the program installed and started the system scan, it maximized the screen resolution and minimized MWB so that when I tried to restore MWB, it would just jump off the viewing area! I was eventually able to get Taskmanager up and locate AV2009 and stop the process, which enabled me to successfully run MWB and purge that nasty piece of crap.

I feel like I just went 10 rounds with Mike Tyson, complete with a bit off ear.
Here's to the good people at Malwarebytes for an excellent product.:toast:

I can't repeat in polite society what I think the assholes who wrote AV2009 should do.:grr:

Think I'll go have a drink now, and look through the Apple catalog. :crazy:
Printer Friendly | Permalink |  | Top
mcctatas Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 12:49 AM
Response to Original message
1. I have no f*ing clue what you just said...
but congratulations :toast:
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 12:55 AM
Response to Reply #1
2. Thanks, and hey, I don't know either...
But if you push enough buttons you can fix anything on these here computin' machines!:silly:

Either that, or get a bigger hammer!
Printer Friendly | Permalink |  | Top
 
mcctatas Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 12:57 AM
Response to Reply #2
3. I usually just cry and bat my eyelashes...
funny, it works to get out of speeding tickets, but I think the computer prefers blonds to redheads :P
Printer Friendly | Permalink |  | Top
 
PaddyBlueEyes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 12:58 AM
Response to Reply #3
4. Ahem
you saw the word kilt...and had a flashback.... :rofl:
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:02 AM
Response to Reply #4
5. Wouldn't that be more of a ...
flashup?:rofl:
Printer Friendly | Permalink |  | Top
 
PaddyBlueEyes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:03 AM
Response to Reply #5
6. rofl
yeah yr right bro.. :rofl:
Printer Friendly | Permalink |  | Top
 
mcctatas Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:09 AM
Response to Reply #4
10. Flashback?
that's not how you spell Org... :P
Printer Friendly | Permalink |  | Top
 
PaddyBlueEyes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:11 AM
Response to Reply #10
11. Ohhh baby
Thats my girl... ILY :evilgrin:
Printer Friendly | Permalink |  | Top
 
Midlodemocrat Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 08:35 AM
Response to Reply #1
31. Here. I'll translate.
He said:

blah, blah, blah, computer, hard drive, SOS, XO, OS, PMS, blah, blah, blah, mouse, monitor, something, turkey, Olive Garden, don't tutch the but, blah, blah, blah, computer, virus, virus, virus, kill, kill, kill.

Got it?
Printer Friendly | Permalink |  | Top
 
mcctatas Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 09:31 AM
Response to Reply #31
32. Oh...
so the same things he usually says then? Thanks Midlo! :P
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 02:27 PM
Response to Reply #32
40. OMG!
I got a two-fer for my DTM list!:rofl:
Printer Friendly | Permalink |  | Top
 
woo me with science Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:03 AM
Response to Original message
7. Hail to you!
Having fought similar battles myself, I raise my glass to you!
Printer Friendly | Permalink |  | Top
 
ghostsofgiants Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:06 AM
Response to Original message
8. Antivirus 2009 is a tricky one.
I'm actually inclined to believe your son.

http://en.wikipedia.org/wiki/Rogue_software
http://en.wikipedia.org/wiki/Antivirus_2009

I've dealt with it a few times, and Malware Bytes is a kickass tool.
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:12 AM
Response to Reply #8
12. They can hide that crap in anything, so I'm sure you're right.
What was amazing though is how hard it fought to keep from getting terminated. Kinda spooky really.
Printer Friendly | Permalink |  | Top
 
ghostsofgiants Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:17 AM
Response to Reply #12
15. The day I built my old computer (this was 4 years ago) I got some spyware from GoldenPalace Casino..
No idea how I even got it, but it was at least an 8 hour job of working to get rid of that fucker. They can really dig in sometimes.
Printer Friendly | Permalink |  | Top
 
Robeson Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:09 AM
Response to Original message
9. That hit mine and my wife's computers....
...it took me a good day to get rid of it...:mad:
Printer Friendly | Permalink |  | Top
 
MrSlayer Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:12 AM
Response to Original message
13. I had that bastard too. Killed it with Webroot Spy Sweeper.
It was a real pain in the ass though. Those virus and malware creators should be castrated.
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:16 AM
Response to Reply #13
14. I'd supply the knife....
Printer Friendly | Permalink |  | Top
 
PaddyBlueEyes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:17 AM
Response to Reply #14
16. Thats awesome
but you should let it rust a little first...
Printer Friendly | Permalink |  | Top
 
MrSlayer Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 03:24 AM
Response to Reply #14
23. A man after my own heart.
Well played. That will do nicely.
Printer Friendly | Permalink |  | Top
 
mwooldri Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 01:43 AM
Response to Original message
17. Excellent !
My colleague at work has just deposited me with two computers that need "cleaning".

One so far in that you can't get to the desktop on XP, you just have your list of users, you click on it and it signs you right back out again.

The other has the infamous Blue Screen of Death.

The first one definitely has a virus on it (he didn't give me the power pack for it - a laptop - and my Antimalware disk cut off half way through scanning when the battery gave out). That's a bit of work but looks like it'll be OK. The second with the BSOD... probably a hardware failure first but then we'll see.

Again well done on kicking the malware! Definitely look at the Apple catalogue, and if you're broke, got spare time on your hands or just otherwise curious check out ubuntu.com and give it a whirl. It does take some getting used to, and if you got some must-have apps that's normally only available on a PC, well it's hard work but possible. (I got Internet Explorer 6 on my Ubuntu setup). (Ubuntu == Linux, if you didn't know already).

Regards, Mark.
Printer Friendly | Permalink |  | Top
 
bluesbassman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 02:05 AM
Response to Reply #17
19. Thanks.
I have a PC that is doing exactly what your first patient is doing. My daughter was using it until she got a Powerbook for school. As we have two other PCs running, and she's welded to the Powerbook now, I haven't been too motivated to tackle it.

I am getting sick of windows, so I just may look into converting. Thanks again! :hi:
Printer Friendly | Permalink |  | Top
 
av8rdave Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 06:10 AM
Response to Reply #19
28. I just "converted" day before yesterday
After watching my kids' experiences with Mac, I finally decided to give Windows the ol' heave ho!
Printer Friendly | Permalink |  | Top
 
DarkTirade Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 02:21 AM
Response to Reply #17
20. Every time someone mentions Ubuntu, I can't help but think of this comic.
Printer Friendly | Permalink |  | Top
 
mwooldri Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 02:43 AM
Response to Reply #20
21. Ha! That works for lots of things...
... shame they got rid of the cool names for the Ubuntu releases and went only to numbers.

Breezy Badger anyone? Hardy Heron?
Printer Friendly | Permalink |  | Top
 
Mollis Donating Member (812 posts) Send PM | Profile | Ignore Fri Jan-23-09 02:02 AM
Response to Original message
18. I used malwarebytes as well.
My boss gave me a copy and it wiped it out. I was very happy about it.
Printer Friendly | Permalink |  | Top
 
SKKY Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 03:02 AM
Response to Original message
22. And that's why I love Linux so much. This kind of stuff doesn't happen to me...
Printer Friendly | Permalink |  | Top
 
sfpcjock Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 04:31 AM
Response to Original message
24. Rootkits that inhabit IE and browsers
I had one of these a year or so ago that claim they are an Anti-virus program for you to buy. They from popular websites :evilgrin: you get if you forgot to do MS Windowsupdate.com and get the patches. I haven't gotten one since that's a "rootkit". Thanks for the cure link.
Printer Friendly | Permalink |  | Top
 
old mark Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 04:35 AM
Response to Original message
25. I had something similar, pretending to be a security program.
I think it came with one of several emails I got from unknown sources recently.
I killed it with Comodo.

mark
Printer Friendly | Permalink |  | Top
 
cemaphonic Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 05:02 AM
Response to Original message
26. Oh yeah, I've crossed paths with that one before.
Total pain.

Take heart though. Most malware writers are in it for kicks and are thus fairly anonymous. Those assholes are trying to make money with that scam and thus have assets to be seized, and criminal defense lawyers in their future.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 05:29 AM
Response to Original message
27. The way I kill crap like this
Edited on Fri Jan-23-09 05:30 AM by hobbit709
1. Turn OFF system restore-If you don't, it will put the crap back on the next boot. Windows acts like
a virus at that point.
2. Reboot into Safe Mode.
3. I keep all the security applications on a flash drive, plug it in and install from there instead of
trying to get online-some of that malware blocks access to any security site.
3 After installing and running scans on all the spyware and antivirus apps, making sure it's gone, then
reboot into normal mode
4. After getting back to the regular desktop, rescan with everything-if the scans come out clean, turn
System Restore back on and reboot one more time.
5. So far this method has worked about 99.9% of the time, though I had a couple of nasties where I had
to use DOS editing commands to get rid of all the traces.
6. I tell people to quit using Internet Exploder. Every infected computer I've seen that is what people
where using. I prefer SeaMonkey which is an integrated browser from Mozilla.
Printer Friendly | Permalink |  | Top
 
Beer Snob-50 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 08:33 AM
Response to Reply #27
30. mozilla is safer than ie?
i just started using that myself. for some reason my family was unable to do many things on the internet using ie (watch video, get on many safe sites)
Printer Friendly | Permalink |  | Top
 
PeaceNikki Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 09:33 AM
Response to Reply #30
33. Not really
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 10:29 AM
Response to Reply #30
37. Two cans on a string is safer than IE
You may have to install the Flashplayer plugin and tweak some of the settings but I haven't found any site that I can't use SeaMonkey on.
Printer Friendly | Permalink |  | Top
 
PeaceNikki Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 07:26 AM
Response to Original message
29. Malwarebytes is THE application to have
Printer Friendly | Permalink |  | Top
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 09:36 AM
Response to Original message
34. I've saved a couple of people who installed it ...
and when it's done, I tell them that if it looks like it's a Windows message, but it's inside a browser window, it's not a Windows message. Close the window - QED.
Printer Friendly | Permalink |  | Top
 
DS1 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 09:40 AM
Response to Original message
35. Programmers who willingly make software like that need to be dragged out into the street and




I'm not fucking kidding. Break their fingers first. Then cut their hands off. Then shoot them in the fucking head.
Printer Friendly | Permalink |  | Top
 
redqueen Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 10:56 AM
Response to Reply #35
38. Do any programmers unwillingly make software like that?
Printer Friendly | Permalink |  | Top
 
DS1 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 11:01 AM
Response to Reply #38
39. Only the ones who have had their car crushed by the classist fascists in the UK
In fact, Billyskank is one speed camera away from writing Anti-Virus2010
Printer Friendly | Permalink |  | Top
 
NJmaverick Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-23-09 09:40 AM
Response to Original message
36. A couple of tricks to beat the nasties
system restore, can sometimes roll back to before you were infected (thus removing the program). This is losing its effectiveness though, as malware writers are starting to disable this feature.

Windows safemode often makes it easier to defeat the nasties as this mode often prevents the programs from being installed.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 02:39 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC