Page 1 of 1

Viral Rogue Antivirus Software

Posted: Thu Mar 25, 2010 12:31 am
by ghhyrd
I've had the joy of weeding these motherfuckers out of my PC once or twice during the past month, has anyone else encountered one of these?

They are pretty nasty, installing themselves without your permission, posing as official Vista/ XP sofware, and bombarding you with messages about imaginary infections until you send a cheque for "A Large Sum Of Cash Only" to "Generic Shady Recipient".

Worse yet they seem to alter your registries, stopping you from accsessing Windows Security centre, System Restore, or damaging your existing AV software. I've even heard of variants that disable the use of .exes completely.

The worst thing is that not many Antivirus softwares seem to be able to cope if they are installed at the time of infection. It seems to wait untill you have pulled out your hair over it to do anything.

The fixes I've had to use are mainly replacing the registries it overrides and taking it out manually, after which my AV seems to develop a kind of immunity to each one.

I'm still not entirely sure what is lurking on my hard drive because of it though...

Anyone else had problems with these things?

Posted: Thu Mar 25, 2010 3:20 am
by Matthew
Don't click on the "OMG UR COMPUTER IS INFECTED" web pages?

inb4 "Stop looking at porn".

Posted: Fri Mar 26, 2010 12:57 pm
by Snail
Never had a problem with them.

Posted: Fri Mar 26, 2010 11:51 pm
by Hammer
I had this a couple weeks ago, snag Malwarebytes

http://www.malwarebytes.org/

cleaned the s### right up

Posted: Tue Mar 30, 2010 8:08 am
by kosh
One of my roommates got one of them yesterday. Nasty piece of work.

Posted: Thu Apr 08, 2010 10:55 pm
by ghhyrd
Yeah I fixed them each time with some registry thang so Norton could wake up and kick it's ass

(Inb4 Norton is s###)

Posted: Fri Apr 09, 2010 1:52 am
by ngtm1r
It's not s###, at least not more than anything else. I go back and forth between Norton, AVG, and McAffe.

Posted: Fri Apr 09, 2010 3:42 am
by Matthew
Yeah, it pretty much is...