Thursday, July 29, 2010

AntiVir Solution Pro Virus Alert!

The Antivir virus family has been damaging computers worldwide for only a few months, and now malware creators have designed an even more difficult to delete virus in Antivir Solutions Pro.

Antivir Solutions Pro is a rouge anti-virus software virus that downloads itself from legitimate sites that have been hacked by the virus's programmers. It will install a virus that creates false "virus infection warnings" that block legitimate and safe programs from running to stop you from scanning and removing it with real anti-virus software and encourages you to download other viruses in the guise of the Antivir Software. It will also encourage you to enter your credit card and/or banking information to license a copy of Anitvir Solutions Pro, which is only a ploy to steal from you directly--the software does nothing, it won't even delete the Antivir virus. The virus will continue to download things like keyloggers (viruses that collect and send information on every keystroke you make on your keyboard to hackers that will collect passwords, credit card information, and banking information and use them to rob you blind.)

The virus will also reconfigure your browser settings so that it will only supply another phony infection warning about the site being "unsafe" and not allow you to go to any site besides their fake site that they created to steal your money--many sites will tell you that it can only do this only with Internet Explorer, but I can tell you (from experience) that it can and will do the same for any browser; it just displays the same "Internet Explorer" warning for all browsers, which makes it easy to identify as a phony warning if you're using Chrome or Firefox. This is to stop you from learning about the virus and downloading programs to help you get rid of it.

The first thing you need to do is to go to your browser's "Tools" >> "Options" then, if you have IE or Google Chrome go to "LAN settings" and unclick the box that says "Use proxy server" and apply and close. If you have Firefox, then go "Tools" >> "Options" >> "Advanced" tab >> uncheck "Use same proxy server" and click the "Assign random proxy server..." bubble. Once you apply and close these options, you'll be able to browse the Internet without the virus stopping you.

Then download rkill from the people at bleepingcomputer.com to your desktop. This program will allow you to shutdown the virus before it loads and can block other programs from loading. Make sure it's on your desktop, because the new version of the virus won't let it run no matter what. You'll have to do a hard reboot of your computer from there--meaning, press the power button until your computer shuts down entirely. Then, immediately restart and open in normal mode. There's no sense in trying to load "Safe Mode," because the virus will stop you from loading it. Now, this is important: as soon as Windows loads and you can see your desktop, you'll have a matter of seconds to locate the rkill icon on your desktop and run it before the virus loads and stops all processes from running. If you do it quickly enough, rkill will stop the virus from loading, so you can now download free anti-virus programs that can find and delete the virus.

Once you've successfully run rkill and stopped the virus from loading. You'll need to download  SUPERantiSpyware professional trial software (Malwarebytes' Anti-Malware can't detect or delete this new version of the virus completely), then scan. Once the scan is done, you should see a virus detected that starts with the name "Rouge"--this is the virus. Wait until the scan is completely finished, because you should be able to find the Trojans that allowed the virus to download itself and you'll want to get rid of them as well. Once it's done, you just follow the directions and it will delete all the viruses and spyware it detected. Then it will need to restart, and you should be virus free.

This is a nasty virus made by some mean hackers/thieves. They should be tracked down and prosecuted.

0 comments:

Post a Comment

Please keep comments on-topic, useful, and non-abusive. Also, keep in mind that this is not a sales forum. If you wish to sell a product or service on this site, I encourage you to visit our "Advertise" page by clicking on the navbar above. Any solicitation in a comment, abuse, or off-topic content will be removed immediately.

While we enjoy a good discourse, this is a privately owned and operated blog. We reserve the right to remove any comment for any reason at anytime whatsoever.

 

Copyright © 2010 30 Year-Old Freshman. All rights reserved.
Design by Insight © 2009