Sunday, July 27, 2008

The fake Antivirus scam

I've recently come across a number of PCs infected with the Vista Antivirus 2009 (even Windows XP systems!) and the Antivirus 2009 spyware variants. Other Antivirus 2009 aliases that have recently appeared on the Internet are: XP Antivirus 2008, Ultimate Antivirus 2008 and System Antivirus 2008. These trick the users by appearing to be genuine Microsoft Windows warnings and products but are in fact scams that require a credit card for US$30 to be entered to remove the apparent detected viruses and spyware. Obviously if you pay up nothing happens.

Initially these appear difficult to remove but I've succeeded by:
- downloading, updating and running Spyware Doctor from Google Pack
- using msconfig to remove any suspicious Startup entries
- resetting Internet Explorer to remove any pervasive Browser Help Objects

A cleanup of an infected machine takes about two hours including any Windows and IE7 updates, plus general maintenance work. Additional work could include restoring Windows Update functionality, allowing Task Manager, removing desktop icons, program entries and Control Panel applets.

No comments: