Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Conficker also installs fake antivirus software
news.cnet. ^ | April 10, 2009 | by Elinor Mills

Posted on 04/10/2009 10:21:07 PM PDT by JoeProBono

Researchers have discovered another feature of the Conficker worm that provides an additional clue about the intent of the creators--the worm installs malware that masquerades as antivirus software, Trend Micro said on Friday.

The worm, which has infected millions of Windows-based computers on the Internet, is downloading a program called Spyware Protect 2009 and displaying warning messages saying that the computer is infected and offering to clean it up for $49.95, according to the Trend Micro blog.

(Excerpt) Read more at news.cnet.com ...


TOPICS: Computers/Internet
KEYWORDS: antivirus; conficker; malware; virus; worm
Navigation: use the links below to view more comments.
first 1-2021-35 next last

If you see this pop-up message, chances are your computer is infected with Conficker. The latest feature of the widespread worm is that it installs fake antivirus software on infected machines.

1 posted on 04/10/2009 10:21:08 PM PDT by JoeProBono
[ Post Reply | Private Reply | View Replies]

To: berdie

later


2 posted on 04/10/2009 10:28:06 PM PDT by berdie (Philosophies of the school room in one generation will reflect the government philosophy of the next)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoeProBono; hiredhand

Ubuntu 8.10 have this issue as well Joe ?


3 posted on 04/10/2009 10:29:10 PM PDT by Squantos (Be polite. Be professional. But have a plan to kill everyone you meet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoeProBono

hey thanks joe, I’ll keep an eye out.


4 posted on 04/10/2009 10:31:20 PM PDT by bobby.223
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoeProBono

Oh my - we had that a few days ago. Malware Bytes didn’t find it and neither did my updated McAfee software. We had to backdate to a restore point.

I wonder if there’s anything else I should do?


5 posted on 04/10/2009 10:32:38 PM PDT by babyfreep
[ Post Reply | Private Reply | To 1 | View Replies]

To: Squantos

Hell no.


6 posted on 04/10/2009 10:32:53 PM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 3 | View Replies]

To: JoeProBono

Run shareware program MALWAREBYTES - will remove this crap
along with others that Norton/Microsoft will miss


7 posted on 04/10/2009 10:33:48 PM PDT by njslim
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoeProBono

That window poppped up a couple days ago on my computer. Had a heckuva time getting rid of it.


8 posted on 04/10/2009 10:33:59 PM PDT by Mr. Mojo
[ Post Reply | Private Reply | To 1 | View Replies]

To: babyfreep
I wonder if there’s anything else I should do?

""

9 posted on 04/10/2009 10:34:49 PM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Squantos
Ubuntu Linux?! You mean the nasty, evil operating system that Microsoft tells us that we shouldn't use?!

Lemme check... ... ...

Well...the 18 Linux servers at work (RedHat), my laptop (Ubuntu), my desktop (Debian Etch), two firewalls here at the house (OpenBSD), SP's PC (Ubuntu), and the mail server (Debian Etch) don't have Conficker! I've even got a copy of the nasty little thing and my Linux system doesn't even seem to KNOW how to load it! :-)
10 posted on 04/10/2009 10:34:53 PM PDT by hiredhand (Understand the CRA and why we're facing economic collapse - see my about page.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Squantos

“The reason that we have not seen a real Linux virus epidemic in the wild is simply that none of the existing Linux viruses can thrive in the hostile environment that Linux provides. The Linux viruses that exist today are nothing more than technical curiosities; the reality is that there is no viable Linux virus.”


11 posted on 04/10/2009 10:37:51 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 3 | View Replies]

To: babyfreep

I was infected by the Vundo malware which looked like the one Conficker has on the screen.

I HAD mcAfee as well, and McAfee was NOT able to find it nor block it. I had to download the FREE Spybot S&D plus AVG free which was successful in destroying it. The McAfee subscription ended in February and I sent them a scathing review why I didn’t renew it.


12 posted on 04/10/2009 10:37:55 PM PDT by max americana
[ Post Reply | Private Reply | To 5 | View Replies]

To: babyfreep
I always have two anti-virus software programs just in case one misses something. I also keep two anti-spyware programs as well.

I always disable automatic download settings on my software; I want to be the one to initiate any such activity. Some good anti-virus (freeware) can be found at www.download.com.

I'm a little fanatical about this type of maintenence; I'll sweep everyday alternating software.

13 posted on 04/10/2009 10:41:21 PM PDT by He Rides A White Horse (unite)
[ Post Reply | Private Reply | To 5 | View Replies]

To: babyfreep
This is interesting, it was a link off off CNET.

http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

14 posted on 04/10/2009 10:47:05 PM PDT by He Rides A White Horse (unite)
[ Post Reply | Private Reply | To 5 | View Replies]

To: He Rides A White Horse

Thx. I saw that the other day. Right now, I’m good.


15 posted on 04/10/2009 10:54:38 PM PDT by babyfreep
[ Post Reply | Private Reply | To 14 | View Replies]

To: martin_fierro; JoeProBono; hiredhand

Cool beans !.........thanks Ya’ll !!!

Hope the Easter Beer Bunny is kind to ya all !


16 posted on 04/10/2009 11:03:22 PM PDT by Squantos (Be polite. Be professional. But have a plan to kill everyone you meet)
[ Post Reply | Private Reply | To 6 | View Replies]

To: babyfreep
Good. I'll say again....always initiate your own downloads. Some programs use your own trusted programs to create havoc. For instance, Microsoft Word is requesting access to the internet. Stuff like that.

Good luck and stay secure.

17 posted on 04/10/2009 11:03:43 PM PDT by He Rides A White Horse (unite)
[ Post Reply | Private Reply | To 15 | View Replies]

To: He Rides A White Horse

AND: http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm


18 posted on 04/10/2009 11:03:44 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 13 | View Replies]

To: JoeProBono; babyfreep

Oh yeah. babyfreep, check out post #18. The freeware version isn’t as robust as the shareware, but it has a nice feature for some who don’t know much about ports and other techie stuff. (If this is not you, disregard.) For example if you receive an alert, you can click on a button and it will explain to you the nature of the threat, and what if anything you need to do.


19 posted on 04/10/2009 11:29:56 PM PDT by He Rides A White Horse (unite)
[ Post Reply | Private Reply | To 18 | View Replies]

To: JoeProBono

Popped up on my work computer today despite several virus scans, AdAware scans, and all the Windows updates being installed a few weeks ago.

It’s a file called sysguard.exe that is displaying the fake Anti Spyware 2009 app on your computer - do a search for it on your computer and delete it. There are probably two instances of the file on your HD - delete them both then empty your Recycle basket.

That’s the easy way to get rid of it.


20 posted on 04/10/2009 11:29:59 PM PDT by Rodney Dangerfield (The election is over. Paris Hilton won.)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson