••• Latest Virus Threat

Latest Virus Threat

Antivirus 2009:

Antivirus 2009 is a new rogue anti-spyware program. It is also a clone of Antivirus 2008 - also a rogue, and one that's produced more clones than any other recently. The list of these clones is long: System Antivirus 2008, Ultimate Antivirus 2008, Vista Antivirus 2008, XP Antivirus 2008 etc.

Like any other of it's predecessors, Antivirus2009 uses trojans, such as Zlob or Vundo, to spread. These trojans lurk in porn/warez websites disguised as video codecs, and, upon entering the system, floods the user with popups and fake system notifications, supposedly to inform him of an infection.

While the system at hand may indeed be infected, Antivirus 2009 will inform the user of this regardless of whether it's true or not. The point of this disinformation is to convince the user he is infected and therefore needs an antispyware program to dispose of the threat. The user might click on one of the popups or notifications, all of which claim they will take him to a legitimate security tool, but try to make him purchase Antivirus2009's "licensed version" instead. Antivirus2009 may redirect web browser to antivirus-premium-scan.com, webscannertools.com, googlescanners-360.com, livesecurityinfo.com, antivirusonlivescan.com, bestantivirusscan.com, antivirus-best.com, internetquarantinesite.com, premiumlivescan.com and secureclick1.com websites that sell the malware. Some of these website are not only fraudulent, but they are also malicious. they are capable of installing additional malwares.

Antivirus 2009 is a scam and should be treated as such: do NOT download or buy it.

Ex.

Antivirus 2009 manual removal:

Kill processes:
av2009.exe av2009[1].exe AV2009Install.exe Antivirus2009.exe

Delete registry values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739

HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”

HKEY_CURRENT_USER\Software\Antivirus

Unregister DLLs:
shlwapi.dll wininet.dll

Delete files:
av2009.exe av2009install.exe av2009install_0011.exe av2009[1].exe Antivirus2009.exe ieupdates.exe scui.cpl %program_files%\\antivirus 2009\\av2009.exe %startmenu%\\antivirus 2009\\antivirus 2009.lnk %startmenu%\\antivirus 2009\\uninstall antivirus 2009.lnk winsrc.dll %desktopdirectory%\\antivirus 2009.lnk winsrc.dll ieupdates.exe av2009install_0011.exe av2009install.exe %program_files%\\antivirus 2009\\av2009.exe

Delete directories:
C:\Program Files\Antivirus 2009
 

Témoignages

  • Notre entreprise, le Centre Transmed, utilise les services informatiques de PLC info depuis maintenant près d’un an. Étant dans un domaine où nous disposons d’équipement informatique très spécialisé, il était primordial de s’entourer d’une équipe bien structurée pouvant répondre à nos besoins. C’est pourquoi nous avons fait appel à PLC info qui est doté d’un personnel qualifié, fiable mais avant toute chose, à l’écoute de nos besoins.

    Au-delà de leurs compétences techniques, PLC info se distingue parmi les autres en nous proposant des solutions gagnantes nous permettant d’économiser du temps et de l’argent.

    Nathalie Levesque, Directrice générale, Centre Transmed