Austech



iTrader Today's Posts Donate My Posts Classifieds Site Rules FAQ's
Go Back   Austech > Technology > Security and Privacy
Register Members List Upgrade Account Search Today's Posts Mark Forums Read

Security and Privacy Spyware , Proxies , all security and privacy issues and software.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 25-07-08, 06:57 PM   #1 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,616
Spent time on board: 1 Month, 4 Weeks, 0 Days and 9:43:15
best4less is on a distinguished road
Default Antivirus XP 2008

What the hell,are these things growing on trees LOL
Another one for the collection
I have know idea what the hell my customers are doing to get this crap on there system

Antivirus XP 2008

You can download a removal tool from here and it worked a treat
How to remove Antivirus XP 2008 (Uninstall Instructions)

Hope this helps someone else
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Old 25-07-08, 07:24 PM   #2 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,616
Spent time on board: 1 Month, 4 Weeks, 0 Days and 9:43:15
best4less is on a distinguished road
Default

Man what a classic virus/Trojan it even gives fake Blue Screen of Death LOL
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Old 25-07-08, 09:39 PM   #3 (permalink)
Killer HKS GTR
 
Godzilla's Avatar
 

iTrader: (5)
Join Date: Jul 2008
Location: Melbourne
Posts: 1,024
Spent time on board: 1 Month, 0 Weeks, 0 Days and 13:36:39
Godzilla is on a distinguished road
Default

Quote:
Originally Posted by best4less View Post
I have know idea what the hell my customers are doing to get this crap on there system

Their probably doing the same thing as you and i only diffrence is we know what not to click on and always wear protection.

What did they think they were going to get from a porn site?

Come to think of it your a VD doctor for computers best4less
Godzilla is offline   Reply With Quote
Sponsored Links
Old 25-07-08, 09:46 PM   #4 (permalink)
Quadmeister
 
PhillTheQuad's Avatar
 

iTrader: (7)
Join Date: Jan 2008
Location: nelson bay
Posts: 604
Spent time on board: 2 Weeks, 3 Days and 2:24:14
PhillTheQuad is on a distinguished road
Default

yea it had me the other day until i ran malwarebytes
69 files it had on vista.
think it was av2008's brother actually.
__________________
vote for Luke fundraiser
http://mydreamis.ingdirect.com.au/?id=3635
PhillTheQuad is offline   Reply With Quote
Old 26-07-08, 05:04 PM   #5 (permalink)
Killer HKS GTR
 
Godzilla's Avatar
 

iTrader: (5)
Join Date: Jul 2008
Location: Melbourne
Posts: 1,024
Spent time on board: 1 Month, 0 Weeks, 0 Days and 13:36:39
Godzilla is on a distinguished road
Default

Nice avatar Phill, if only the tearing went up another inch, the world would be a better place.
Godzilla is offline   Reply With Quote
Old 26-07-08, 06:06 PM   #6 (permalink)
Senior Member
 
Woodstock's Avatar
 

iTrader: (14)
Join Date: Jan 2008
Location: Mt Gambier
Posts: 727
Spent time on board: 2 Weeks, 4 Days and 9:46:56
Woodstock is on a distinguished road
Default

had a customer with Antivirus XP 2008 & Antivirus XP 2009 on there lappy .. after couple hrs scanning with above prog removed it .. runs fine now ! haha was funny done fake BSOD then done Windows XP booting in animated thing .. funny thing lappy was running VISTA ! ... was good laugh that 4 sure
__________________
Trust thyself only, and another shall not betray thee.
Woodstock is offline   Reply With Quote
Sponsored Links
Old 28-07-08, 10:22 PM   #7 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,616
Spent time on board: 1 Month, 4 Weeks, 0 Days and 9:43:15
best4less is on a distinguished road
Default

LOL and another,the customers phones me tonight and says he needs a new computer
He will be a happy camper Tomorrow
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Old 28-07-08, 10:27 PM   #8 (permalink)
Killer HKS GTR
 
Godzilla's Avatar
 

iTrader: (5)
Join Date: Jul 2008
Location: Melbourne
Posts: 1,024
Spent time on board: 1 Month, 0 Weeks, 0 Days and 13:36:39
Godzilla is on a distinguished road
Default

You mean you will be the happy camper after you sell him a new one and trade in his worthless old one.
Godzilla is offline   Reply With Quote
Old 28-07-08, 10:31 PM   #9 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,616
Spent time on board: 1 Month, 4 Weeks, 0 Days and 9:43:15
best4less is on a distinguished road
Default

LOL I have enough computers not enough cash
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Sponsored Links
Old 28-07-08, 10:39 PM   #10 (permalink)
Killer HKS GTR
 
Godzilla's Avatar
 

iTrader: (5)
Join Date: Jul 2008
Location: Melbourne
Posts: 1,024
Spent time on board: 1 Month, 0 Weeks, 0 Days and 13:36:39
Godzilla is on a distinguished road
Default

Rule No1,The customer is always right.

Just dont tell him it could be fixed.
Godzilla is offline   Reply With Quote
Old 15-08-08, 06:07 PM   #11 (permalink)
mxd
Premium Member
 

iTrader: (4)
Join Date: Feb 2008
Posts: 71
Spent time on board: 3 Days and 5:09:00
mxd is on a distinguished road
Default

Hi Guys,

I got this and finally got rid of it with MBAM but now mcaffee keeps telling me I have a virus W32/PEPatcher.c in my winlogon.exe.

Has any one else seen this ?

thanks
Matt
mxd is offline   Reply With Quote
Old 22-08-08, 07:39 PM   #12 (permalink)
Junior Member
 

iTrader: (0)
Join Date: Mar 2008
Posts: 9
Spent time on board: 1:19:40
W0rp3D is on a distinguished road
Default

I have this virus but i cant get to any of the sites to download a fix, any chance of someone putting it up or sending it to bridgeport13b@gmail.com

Any help would be appreciated.

BTW i think it may have come from ipmart.com everything was fine till i went there to get an app for my n95.
W0rp3D is offline   Reply With Quote
Sponsored Links
Old 22-08-08, 07:51 PM   #13 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,616
Spent time on board: 1 Month, 4 Weeks, 0 Days and 9:43:15
best4less is on a distinguished road
Default

It's almost a 15 meg download. You would have upgraded your computer twice by the time my internet would have uploaded it to you
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Old 22-08-08, 08:36 PM   #14 (permalink)
Quadmeister
 
PhillTheQuad's Avatar
 

iTrader: (7)
Join Date: Jan 2008
Location: nelson bay
Posts: 604
Spent time on board: 2 Weeks, 3 Days and 2:24:14
PhillTheQuad is on a distinguished road
Default

Quote:
Originally Posted by W0rp3D View Post
I have this virus but i cant get to any of the sites to download a fix, any chance of someone putting it up or sending it to bridgeport13b@gmail.com

Any help would be appreciated.

BTW i think it may have come from ipmart.com everything was fine till i went there to get an app for my n95.

sent u malwarebytes,should fix it

Q
__________________
vote for Luke fundraiser
http://mydreamis.ingdirect.com.au/?id=3635
PhillTheQuad is offline   Reply With Quote
Old 23-08-08, 01:47 PM   #15 (permalink)
Premium Member
 
Helen's Avatar
 

iTrader: (2)
Join Date: Jan 2008
Location: Cyber Space
Posts: 269
Spent time on board: 1 Day and 20:58:22
Helen is on a distinguished road
Default

Prick of a thing this is
I got it the other day...didnt bother trying to fix it...formatted and fixed.
So many peeps are getting this one....its a pain in the butt.lol
Helen is offline   Reply With Quote
Sponsored Links
Old 23-08-08, 01:56 PM   #16 (permalink)
Senior Member
 
Woodstock's Avatar
 

iTrader: (14)
Join Date: Jan 2008
Location: Mt Gambier
Posts: 727
Spent time on board: 2 Weeks, 4 Days and 9:46:56
Woodstock is on a distinguished road
Default

no need to format .. the prog recommended above removes it for good !
__________________
Trust thyself only, and another shall not betray thee.
Woodstock is offline   Reply With Quote
Old 23-08-08, 02:12 PM   #17 (permalink)
Senior Member
 

iTrader: (0)
Join Date: Jan 2008
Location: Cranebrook, NSW
Posts: 100
Spent time on board: 17:05:17
therufus is on a distinguished road
Default

Update your Java!

I'm not sure how accurate this information is, but I heard that these parasites can get shoved in via an exploit in older versions of Java. Head to java.com: Java + You and get the latest version.
therufus is offline   Reply With Quote
Old 24-08-08, 05:22 PM   #18 (permalink)
Quadmeister
 
PhillTheQuad's Avatar
 

iTrader: (7)
Join Date: Jan 2008
Location: nelson bay
Posts: 604
Spent time on board: 2 Weeks, 3 Days and 2:24:14
PhillTheQuad is on a distinguished road
Default

i actually had someone that paid their fee of 100 or watever only to whatch me remove it 1 hour later lol.

Win Antivir 2008 Manual Removal Process:

1. Click on the Start Menu button, then click on the Control Panel option, and then Double-click on the Add or Remove Programs icon.

2. Locate Win Antivir 2008 and double-click on it to uninstall Win Antivir 2008. Follow the screen step-by-step screen instructions to complete uninstallation of Win Antivir 2008. Do not worry about this if you cannot find it in Add/Remove window. Simply skip to #5.

3. Restart the computer.

4. When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.

5. Close all programs.

6. Search and delete the following infected entries in registry. If you do not know how to edit registry, click here to read more.

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run “Win Antivir 2008″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run “Win Antivirus 2008″

7. Stop Win Antivir 2008 process. If you do not know how to stop a running process, click here to read more.

8. Find and delete the following infected files or directories from your system. Don’t worry if you don’t find these files. Just proceed to next step.

Win Antivir 2008.exe
Win Antivirus 2008.exe
Win Antivir 2008.dll
Win Antivir 2008.lnk
Win Antivirus 2008 Uninstall.lnk
c:\Program Files\Win Antivirus 2008

If you do not know how to find it or having difficulties locating the file, click here to read more.

9. Rename the files that you found above to “foundbadfile1.dll” and “foundbadfile2.dll” (if you can not rename this file, then try to restart your computer in safe mode then try to rename this file.) If you don’t know how to start the computer in safe mode, click here to read more.

10. Go to C:\Program Files\ folder and delete the “Win Antivir 2008″ folder (if you can’t delete it, reboot your computer to safe mode then delete the folder. Do not worry about it if you can’t find this folder.)

11. Click here to bookmark this page (you will need to comeback to this page after reboot)
(If you are using Firefox click on Ctrl+D on your keyboard to bookmark this page)

12. Restart your computer

13. Go to your computer and delete the “foundbadfile1.dll” and “foundbadfile2.dll” file

14. You have just removed Win Antivir 2008 from your computer manually.

Win Antivir 2008 Removal Process (remove WinAntivir2008) - PCHubs.com
__________________
vote for Luke fundraiser
http://mydreamis.ingdirect.com.au/?id=3635
PhillTheQuad is offline   Reply With Quote
Sponsored Links
Old 24-08-08, 05:35 PM   #19 (permalink)
Quadmeister
 
PhillTheQuad's Avatar
 

iTrader: (7)
Join Date: Jan 2008
Location: nelson bay
Posts: 604
Spent time on board: 2 Weeks, 3 Days and 2:24:14
PhillTheQuad is on a distinguished road
Default

and how easy is it to get !
go to win-antivirus-2008 and see,or get the popup
the trick is,dont click ok, dont click anything.
even clicking cancel doesnt worry this thing.
bring up the task manager and kill the page url.
__________________
vote for Luke fundraiser
http://mydreamis.ingdirect.com.au/?id=3635
PhillTheQuad is offline   Reply With Quote
Old 24-08-08, 05:41 PM   #20 (permalink)
Super Moderator
 
Sanity's Avatar
 

iTrader: (5)
Join Date: Jan 2008
Location: Victoria
Posts: 2,904
Sanity is on a distinguished road
Default

Quote:
Originally Posted by therufus View Post
Update your Java!

I'm not sure how accurate this information is, but I heard that these parasites can get shoved in via an exploit in older versions of Java. Head to java.com: Java + You and get the latest version.

I would say its not accurate. This thing is everywhere , my missus copped it on the screen after clicking on a link in a Google search while studying the other day. The OS was only installed a couple of weeks ago.

It can pop up on a web page and soon as you click on it , you are stuck with it Its pop up boxes look like a genuine program and many people will click on it without thinking.
Sanity is offline   Reply With Quote
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


server monitor
All times are GMT +10. The time now is 11:16 PM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

Ad Management by RedTyger