<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; av2009</title>
	<atom:link href="http://blog.novirusthanks.org/tag/av2009/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How to remove Antivirus 2009</title>
		<link>http://blog.novirusthanks.org/2008/10/antivirus-2009-rogue-software/</link>
		<comments>http://blog.novirusthanks.org/2008/10/antivirus-2009-rogue-software/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 12:59:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[antivirus 2009]]></category>
		<category><![CDATA[av2009]]></category>
		<category><![CDATA[rogue]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=86</guid>
		<description><![CDATA[Antivirus 2009 is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim. &#160; Once your computer is infected with this parasite, it will immediately displays security [...]]]></description>
			<content:encoded><![CDATA[<p>Antivirus 2009 is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim.</p>
<p>&nbsp;</p>
<p>Once your computer is infected with this parasite, it will immediately displays security warnings, alerts and system scans stating that your computer is heavily infected. These warnings are all false and are only displayed to make you think your computer is truly infected and that it is necessary to buy the full version of the software to remove the so-called infections.</p>
<p>&nbsp;</p>
<p>Make sure to not fall in this scam, if your computer is infected with Antivirus 2009, it is recommended to remove it immediately and to scan your system with a real security software.</p>
<p>&nbsp;</p>
<p><b>Symptoms of infection</b></p>
<p>&nbsp;</p>
<ul>
<li> The process av2009.exe is running in your system</li>
<li> The process ieupdates.exe is running in your system</li>
<li> Slow computer performance</li>
<li> Repeated security warnings, alerts and system scans</li>
<li> Web sites that suddenly are shown on your desktop</li>
</ul>
<p>&nbsp;</p>
<p>Malicious web sites and urls:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">online-antivirus.net
antiviruspersonaltest.com
bulkwatcher.com</pre></td></tr></table></div>

<p>Internet traffic on port 80:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /2009/100/freescan.php?id=880799 HTTP/1.1
Referer: hxxp://online-antivirus.net/
Connection: Keep-Alive
Host: antiviruspersonaltest.com
&nbsp;
GET /2009/download/trial/A9installer_880799.exe HTTP/1.1
Referer: hxxp://online-antivirus.net/
Range: bytes=69796-
Connection: Keep-Alive
Host: antiviruspersonaltest.com</pre></td></tr></table></div>

<p>When the program is executed, it creates the following files:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">%UserProfile%\Desktop\Antivirus 2009.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
%UserProfile%\Start Menu\Antivirus 2009
%UserProfile%\Start Menu\Antivirus 2009\Antivirus 2009.lnk
%UserProfile%\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk
%ProgramFiles%\Antivirus 2009
%ProgramFiles%\Antivirus 2009\av2009.exe
c:\WINDOWS\system32\ieupdates.exe
c:\WINDOWS\system32\scui.cpl
c:\WINDOWS\system32\winsrc.dll</pre></td></tr></table></div>

<p>The program creates the following registry entries:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKLM\SOFTWARE\Av2009
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Av2009
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ieupdate</pre></td></tr></table></div>

<p>How to remove Antivirus 2009 (manual removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Kill the running process av2009.exe</li>
<li> Kill the running process ieupdates.exe</li>
<li> Unregister all the Antivirus 2009 DLLs</li>
<li> Delete all the Antivirus 2009 files</li>
<li> Delete all the Antivirus 2009 registry entries</li>
</ul>
<p>&nbsp;</p>
<p>How to remove Antivirus 2009 (automatic removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Download and Install <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/" target="_blank" title="Free Malware Remover">NoVirusThanks Malware Remover</a></li>
<li> Update the database</li>
<li> Click the button Scan</li>
<li> Delete infected files</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/10/antivirus-2009-rogue-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

