Southern Maryland Online - Serving Calvert, Charles, & St. Mary's Counties.  Click here to go to the Front Page of somd.com.
 
| Write Us | Help | Sponsors | Classifieds | Employment | Forums | MarketPlace | Calendar | Headlines | Announcements | Weather | More... |


Go Back   Southern Maryland Community Forums > General Interest > Computers, Technology, & the Internet
Register Blogs FAQ Members List Calendar Chat Search Today's Posts Mark Forums Read Wireless

Computers, Technology, & the Internet Talk about computers, the net and the latest technology, e.g. music, video, wireless, you name it. Who do you love more? Your wife or your Tivo?

Reply
 
LinkBack Thread Tools Display Modes
Old 01-30-2009, 08:42 AM   #1 (permalink)
Rocky Mountain High!!
 
happyappygirl's Avatar
 
Member Since: May 2004
Location: Quiet Valley Farm
Posts: 5,405
AV2009 virus - causes fake security popups

AV2009 the fake anti-virus

My PC became infected this week, I'm assuming from the kidlet visiting MySpace (a favorite infection site)...it whacked my AVG antivirus and firewall, AND the downloaded new version of AVG. It bogged the pc down, and eventually froze it. I often had to reboot twice to be able to even use it. It was a real pain.

According to my research, it primarily gains access through acceptance of 3rd party cookies and 'Active 'X' which in this case displays some type of security icon, or pop-up warning, which in reality is a 'Click-jacking' whereby the real action you perform is hidden behind the visible display; so when you tick anything, the malware installs itself.

Unlike typical pop-up advertising (stopped with available blockers) 3rd party cookies are entirely different critters. The recommendation is to turn off "3rd Party Cookies", and always leave them off.

INTERNET EXPLORER: Tools> Internet Options> Privacy> Advanced: here check 'Override automatic....'; 'Allow session cookies'; 'Allow 1st party cookies'; & 'Block 3rd Party Cookies'.

FIREFOX: Tools> Options> Privacy: here UN-CHECK 'Accept 3rd Party cookies'
Because architecture of the Internet (notably 'Flash' scripting), vulnerabilities are readily exploited in Internet Explorer, & it is now urgent that you use
Firefox with current 'NoScript' add-on, which will prevent "Click-jacking'.
NoScript: https://addons.mozilla.org/en-US/firefox...

I had to download and install a Malware program Malwarebytes.org to wipe it off my pc. The malware program found over 100 infected files, including ROOT files. I then had to download AVG again, and rescanned the pc. The rescan with AVG 8.0 found an additional 80 or so temp files to delete!
__________________
Everything will be ok in the end. If it's not ok, it's not the end.
http://www.qvmountainhorses.com
happyappygirl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 01-30-2009, 08:46 AM   #2 (permalink)
Pretty Boy/Guardian Angel
 
warneckutz's Avatar
 
Member Since: Mar 2006
Location: The Gym
Posts: 12,371
I've removed this virus from about 5 different computers. I found a program by Malwarebytes - "Anti-Malware". Seemed to solve the AV2009 problem on all of the systems.
__________________
Listen to me now, and believe me later: it doesn't matter how much you pump up those muscles, as long as you reach the full pumptential.

***AMAZING***

Training for 2010 Goal:
200lbs
6%bf


"fecal matter just got tangible"
warneckutz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 01-30-2009, 08:50 AM   #3 (permalink)
Rocky Mountain High!!
 
happyappygirl's Avatar
 
Member Since: May 2004
Location: Quiet Valley Farm
Posts: 5,405
Quote:
Originally Posted by warneckutz View Post
I've removed this virus from about 5 different computers. I found a program by Malwarebytes - "Anti-Malware". Seemed to solve the AV2009 problem on all of the systems.
did u read my post?
I used the same software.
__________________
Everything will be ok in the end. If it's not ok, it's not the end.
http://www.qvmountainhorses.com
happyappygirl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 01-30-2009, 08:55 AM   #4 (permalink)
Yeah, okay.
 
rwethereyet's Avatar
 
Member Since: Mar 2008
Location: Land of the misfits....
Posts: 913
Quote:
Originally Posted by happyappygirl View Post
AV2009 the fake anti-virus

My PC became infected this week, I'm assuming from the kidlet visiting MySpace (a favorite infection site)...it whacked my AVG antivirus and firewall, AND the downloaded new version of AVG. It bogged the pc down, and eventually froze it. I often had to reboot twice to be able to even use it. It was a real pain.

According to my research, it primarily gains access through acceptance of 3rd party cookies and 'Active 'X' which in this case displays some type of security icon, or pop-up warning, which in reality is a 'Click-jacking' whereby the real action you perform is hidden behind the visible display; so when you tick anything, the malware installs itself.

Unlike typical pop-up advertising (stopped with available blockers) 3rd party cookies are entirely different critters. The recommendation is to turn off "3rd Party Cookies", and always leave them off.

INTERNET EXPLORER: Tools> Internet Options> Privacy> Advanced: here check 'Override automatic....'; 'Allow session cookies'; 'Allow 1st party cookies'; & 'Block 3rd Party Cookies'.

FIREFOX: Tools> Options> Privacy: here UN-CHECK 'Accept 3rd Party cookies'
Because architecture of the Internet (notably 'Flash' scripting), vulnerabilities are readily exploited in Internet Explorer, & it is now urgent that you use
Firefox with current 'NoScript' add-on, which will prevent "Click-jacking'.
NoScript: https://addons.mozilla.org/en-US/firefox...

I had to download and install a Malware program Malwarebytes.org to wipe it off my pc. The malware program found over 100 infected files, including ROOT files. I then had to download AVG again, and rescanned the pc. The rescan with AVG 8.0 found an additional 80 or so temp files to delete!

I wonder if this is my problem? I had AVG on my computer, and I got a message that it was outdated. I had AVG 8.0 installed on there. I uninstalled the AVG 8.0 and when I tried to reinstall it, it wouldn't let me. I'll try to download the above Malware program and then try to reinstall AVG.
__________________
Quote:
Originally Posted by delfromlb View Post
It baffles me on a daily basis and I must just chalk it up to sheer ignorance...or boredom.
rwethereyet is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 01-30-2009, 08:56 AM   #5 (permalink)
Pretty Boy/Guardian Angel
 
warneckutz's Avatar
 
Member Since: Mar 2006
Location: The Gym
Posts: 12,371
Quote:
Originally Posted by happyappygirl View Post
did u read my post?
I used the same software.
Oh crap, sorry! Short attention span mixed with some side reading and iTunes shuffling... sorry!
__________________
Listen to me now, and believe me later: it doesn't matter how much you pump up those muscles, as long as you reach the full pumptential.

***AMAZING***

Training for 2010 Goal:
200lbs
6%bf


"fecal matter just got tangible"
warneckutz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 01-30-2009, 09:11 AM   #6 (permalink)
Rocky Mountain High!!
 
happyappygirl's Avatar
 
Member Since: May 2004
Location: Quiet Valley Farm
Posts: 5,405
Quote:
Originally Posted by rwethereyet View Post
I wonder if this is my problem? I had AVG on my computer, and I got a message that it was outdated. I had AVG 8.0 installed on there. I uninstalled the AVG 8.0 and when I tried to reinstall it, it wouldn't let me. I'll try to download the above Malware program and then try to reinstall AVG.
That's exactly what happened to mine. The popup window was IE, and the antivirus outdated msg was from Norton Antivirus, and i use AVG and Mozilla, so i knew i had something going on.
you'll prolly have to uninstall and download AVG again. The virus corrupts install files even on the zipped version. I downloaded it again after i wiped the virus out.
Make sure you run a full AVG scan again after you run the malware. You'll be surprised at how many files were left.
__________________
Everything will be ok in the end. If it's not ok, it's not the end.
http://www.qvmountainhorses.com
happyappygirl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 03-04-2009, 12:11 AM   #7 (permalink)
Registered User
 
Member Since: Aug 2008
Posts: 2
SpyBot Search and destroy does a good job as well. http://www.safer-networking.org/en/home/index.html It has saved me in the past.
Dan_Daly is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 03-04-2009, 02:43 PM   #8 (permalink)
Registered User
 
Member Since: Feb 2009
Posts: 66
AV2009 is a nasty little bugger. I've removed it from so many peoples pc's. I've had people come to my bank closing their accounts because they actually paid for the program since it says you have to download it to fix the problem. I use SmitFraudFix. Works Great. Easy to use. And a tiny program.
TotalEclipse31 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 03-04-2009, 05:10 PM   #9 (permalink)
Registered User
 
Member Since: Dec 2008
Posts: 154
Quote:
Originally Posted by happyappygirl View Post
AV2009 the fake anti-virus

My PC became infected this week, I'm assuming from the kidlet visiting MySpace (a favorite infection site)...it whacked my AVG antivirus and firewall, AND the downloaded new version of AVG. It bogged the pc down, and eventually froze it. I often had to reboot twice to be able to even use it. It was a real pain.

According to my research, it primarily gains access through acceptance of 3rd party cookies and 'Active 'X' which in this case displays some type of security icon, or pop-up warning, which in reality is a 'Click-jacking' whereby the real action you perform is hidden behind the visible display; so when you tick anything, the malware installs itself.

Unlike typical pop-up advertising (stopped with available blockers) 3rd party cookies are entirely different critters. The recommendation is to turn off "3rd Party Cookies", and always leave them off.

INTERNET EXPLORER: Tools> Internet Options> Privacy> Advanced: here check 'Override automatic....'; 'Allow session cookies'; 'Allow 1st party cookies'; & 'Block 3rd Party Cookies'.

FIREFOX: Tools> Options> Privacy: here UN-CHECK 'Accept 3rd Party cookies'
Because architecture of the Internet (notably 'Flash' scripting), vulnerabilities are readily exploited in Internet Explorer, & it is now urgent that you use
Firefox with current 'NoScript' add-on, which will prevent "Click-jacking'.
NoScript: https://addons.mozilla.org/en-US/firefox...

I had to download and install a Malware program Malwarebytes.org to wipe it off my pc. The malware program found over 100 infected files, including ROOT files. I then had to download AVG again, and rescanned the pc. The rescan with AVG 8.0 found an additional 80 or so temp files to delete!
I think I have this :(
latiger12 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 03-04-2009, 05:48 PM   #10 (permalink)
Registered User
 
Member Since: Feb 2009
Posts: 66
LATIGER, Use any of the programs mentioned above and it should fix it for you. Just let us know if you have any questions.
TotalEclipse31 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 08:24 PM.



| Home | Help | Contact Us | About somd.com | Privacy | Advertising | Sponsors | Newsletter |

| What's New | What's Cool | Top Rated | Add A Link | Mod a Link | Link to Us |

| Announcements | Bookstore | Chat | Calendar | Classifieds | Community |
| Contests & Surveys | Culture | Dating | Dining | Education | Employment | Entertainment |
| Forums | Free E-Mail | Games | Gear! | Government | Guestbook | Health | Marketplace | Mortgage | News |
| Organizations | Photos | Postcard | Real Estate | Relocation | Sports | Survey | Travel | Wiki | Weather | Worship |

Brought to you by Virtually Everything, Inc.   ©1996-2009, All rights reserved.


SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.