Burlington Iowa Computer and Business Consulting Firm
Contact Us      Links      Intranet   
Drake Hardware and Software

 Services
 Company
TurnKey Creations

Click here to go to our online support center.

Drake is an authorized partner of Aldelo Systems.

NFIB represents the interest of small and independent business owners before federal and state legislative and executive branches of government. As a matter of policy, NFIB does not endorse or promote the products and services of its members.

Trojan Alert - August 18th, 2008

Antivirus 2008 and 2009
Drake Hardware & Software

A new pest that is infecting computers is Antivirus 2008 and its newer version Antivirus 2009. They are not antivirus programs. They are malware programs which give you pop ups about cleaning your computer with their product. These programs usually cannot be caught by your updated antivirus. It takes an updated constantly running antispyware program.

The offending programs sometimes come in an email that seems to be sent from admin@microsoft.com in order to make it look legitimate. The download link "Download the latest version Internet Explorer 7.0? points to a URL that may look like this:

http://89.187.49.18/IE-7.0.exe

Downloading this malware file to the system results in for example additional downloads of malware onto the infected system, in this case the Rogue application Antivirus XP 2008. This rogue Creates files in System32 and a folder in Program files with random names making it hard to remove and the files are also continuously modified in order to avoid detection.

It can also install from a "Google Tip". A page that pops up and looks like a legitimate Google page and tells you that your system is infected. And you should download Antivirus 2008 or 2009 to clean it.

The registry is also modified in order to make the installed malware run at system startup. Antivirus XP 2008, and other Rogue applications generates exaggerated threat reports on the compromised computer trying to make the user believe that the system is heavily infected and then asking the user to purchase a registered version of the Rogue application to remove the reported threats as the removal function is deactivated in the unregistered version of the Rogue.

The user desktop wallpaper may also be changed with the help of a few registry modifications.

There are a few fixes for this. Buy the professional version of Ad-Aware or SuperAntiSpyware, or after your computer has been infected install and update the free version of SuperAntiSpyware and run it, or download and run Smitfraudfix.

-From the Lavasoft.com blog-









Corporate Headquarters
Drake Hardware & Software
211 N. 5th St., Ste 100
Burlington, IA 52601-5316
Phone: 319.752.1155
Fax: 319.752.2299

Oskaloosa Area Connection
Drake Hardware & Software
Phone: 319.752.1155

TurnKey Creations
211 N. 5th St., Ste 100
Burlington, IA 52601-5316
Phone: 319.752.9898