Friday, August 8, 2008

AntiVirus XP 2008 or 2009


Antivirus XP 2008 is a widespread bogus antivirus application for Windows that was promoted and downloaded automatically by redirecting users internet browser to its predefined website.

Miscellaneous threats include applications that do not fit into other categories or that fall into multiple categories. Miscellaneous threats typically include some form of potentially objectionable functionality that may pose privacy or security risks to users and their PCs.

It a Rogue Security Program is software that purports to scan and detect malware or other problems on the computer, but which attempts to dupe or badger users into purchasing the program by presenting the user with intrusive, deceptive warnings and/or false, misleading scan results. Rogue Security Programs typically use aggressive, deceptive advertising and may be installed without adequate notice and consent.

what are the issues:

It is typically installed without adequate notice and consent, and may make unwanted changes to your system, such as reconfiguring your browser's homepage and search settings. These risks may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect your preferred network connections, and can negatively impact your computer's performance and stability. Elevated risks may also collect, transmit, and share potentially sensitive data without adequate notice and consent.

To remove it: - not easy as its changing its name, moves around. - there is a Antivirus XP Removal Tool (DO NOT USE, its by the same people and infects your machine more)



Delete these File Traces :

%LOCAL_SETTINGS%\ temp\ .tt10.tmp.exe
%PROGRAM_FILES%\ rhc75vj0ead3\ rhc75vj0ead3.exe
%PROGRAM_FILES%\ rhca3rj0er43\ rhca3rj0er43.exe
%SYSTEM%\ blphcancj0e915.scr
%SYSTEM%\ lphc35vj0ead3.exe
%SYSTEM%\ lphccm2j0endc.exe
%SYSTEM%\ lphce3rj0er43.exe
%SYSTEM%\ lphcp02j0er35.exe
%system%\ lphctq7j0etdc.exe
%SYSTEM%\ lphcvksj0ev6j.exe
%SYSTEM%\ pphc35vj0ead3.exe
%SYSTEM%\ pphce3rj0er43.exe
%SYSTEM%\ pphcp02j0er35\ pphcp02j0er35.exe
.tt4.tmp.exe
1.exe
antivirscanner.exe
antivirusxp.exe
antivirusxp2008_scan.exe
AntivirusXP2008Installer.exe
autorun.exe
av.exe
AV2008install.exe
av2009install_880147.exe
b62ac658-164f-4e2d-a34b-c437a9e8b34b.exe
bill.exe
bwpkjqjk.exe
C:\ Program Files\ rhclmpj0e9cn\ rhclmpj0e9cn.exe
darkmind.exe
e-card.exe
efa1ec37-375b-45ce-94b5-9f2c6247eed6.exe
freescan.exe
gtinqpuh.exe
IE-7.0.exe
index.exe
inst2_294.exe
install.exe
install_4849.exe
limbage12.exe
lphc5tej0e1c9.exe
lphc7ujj0et79(2).exe
lphc7ujj0et79.exe
lphcancj0e915.exe
lphcedoj0el5c.exe
lphcp0qj0e10j.exe
madonna.avi.exe
name.avi.exe
pphcancj0e915.exe
rarara.exe
rhc3ujj0et79.exe
rhcencj0e915.exe
rhcencj0e915Skin.dll
scan(2)_1.exe
scan.exe
scann.exe
setup.exe
setup_110084_3_.exe
sunfor54.exe
suny790.exe
system32\ lphc35vj0ead3.exe
video-nude-anjelina.avi.exe
video-paris-hilton.avi.exe
video.avi.exe
videoxxx.avi.exe
virusremover.dll
XPantivirus2008_v880021.exe

Please not this list will just grow and grow, as it changes its name by itself..
Here are some pictures of what this looks like









No comments: