Devirusare AVDefender 2011

Despre cum se “agata” un rogue de pe net. “Procedura” decurge cam asa:

AVDefender2011

AVD2011

Detectie VirusTotal.
AVDefender2011, este un rogue,(un program antivirus/antispyware fals). Dupa ce s-a instalat AVDefender 2011,
inlocuieste Windows explorer.exe, acest lucru permite programului sa porneasca automat, când porniţi Windows-ul.Dupa pornire incepe si scaneaza si va anunta ca sunteti infectat. Toate infectiile gasite sunt false. Prin urmare, nu
incercati sa stergeti manual, infectiile anuntate de AVDefender2011.În timp ce ruleaza, AVDefender 2011 nu vă va
permite să rulaţi majoritatea programelor. Face acest lucru pentru a se proteja de programele anti-virus legitime,
care pot încerca să-l elimine. Când încercaţi să rulati un program se va afisa o alertă care să ateste că programul
este infectat şi apoi inchide programul.
Mesajele afisate sunt:

Windows Security Alert! Application NOTEPAD.EXE has crashed because of Conficker.Worm.Virus

Infected file: notepad.exe

Potential Risks: Viruses is spreading over your PC and the system status is unsafe. Your service provider may lock you out of internet access, because your PC is potentially harmful.

Viruses’ actions:

Steal your personal data and send it to the remote host. Spread between your friends quickly (via internet or storage drives). Send spam and malicious codes from your computer.

AVDefender 2011, va afişa alerte de securitate false:

System warning: Unknown virus is harming your system at this moment. Click here to stop and remove the virus.

Critical security error! Malicious software has infected your PC and trying to send private information to remote host 231.21.212.1.

Warning! System health status is critical! Your computer is infected with viruses. Stability and reliability of your system is damaged. It is strongly recommended to remove threats immediately.

Cand porniti Internet Explorer, va anunta ca Google a gasit o vulnerabilitate in Windows:

Google Security Warning! We have discovered a vulnerability related to Microsoft software that could allow a virus or other malicious program to harm your system or personal files or to steal personal information stored on your computer.

Toate aceste alerte, sunt false! AVDefender 2011 utilizează aceste alerte, pentru a va face sa credeti ca aveti computerul infectat!

Creaza si modifica urmatoarele fisiere:

  • C:Documents and Settings\%USER%\Application Data\AVDefender2011\AVDefender2011.ini
  • C:Documents and Settings\%USER%\Application Data\AVDefender2011\history.dat
  • C:Documents and Settings\%USER%\Application Data\AVDefender2011\result.dat
  • C:Documents and Settings\%USER%\Application Data\AVDefender2011\vlc.dat
  • C:Documents and Settings\%USER%\Application Data\unevvpfar\sk.lst
  • C:Documents and Settings\%USER%\Application Data\unevvpfar\zdzjpoud.exe
  • C:Documents and Settings%USER%Start MenuAVDefender2011AVDefender2011.lnk

Modificari in Windows Registry:

HKEY_CURRENT_USER\Software\AVDefender 2011
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = “%AppData%\\.exe”

Intrarea din log-ul HijackThis este urmatoare:
F2 – REG:system.ini: Shell=C:\Documents and Settings\%User%\Application Data\\.exe

DEVIRUSARE:



1. Descarcati Malwarebytes Anti-Malware.
Redenumiti fisierul mbam-setup.exe in iexplore.exe si rulati-l. La finalul instalarii debifati Update Malwarebytes’ Anti-Malware si Launch Malwarebytes’ Anti-Malware.

2. Navigati in folder-ul C:\program files\Malwarebytes’ Anti-Malware\ si redenumiti mbam.exe in iexplore.exe.
Rulati acum executabilul redenumit anterior, scanati PC-ul complet si stergeti la final infectiile gasite apasand Remove selected.

Daca ai reusit sa cureti aceasta infectie, iti recomand sa cumperi versiunea PRO a Malwarebytes Anti-Malware pentru a te proteja si pe viitor de astfel de amenintari, avand in vedere ca nu au fost detectate\eliminate de antivirusul tau actual.

Malware Hunters pentru Malwarebytes’ Anti-Malware

4 responses to “Devirusare AVDefender 2011”

  1. Marius(MariusNo1)

    Malwarebytes pro e mai bun ca oricare antivirus?

    1. Radu FaraVirusi(com)

      @Marius: Malwarebytes Pro este mai bun ca oricare antivirus cand vine vorba de protectia impotriva spyware\adware\antivirusi falsi si chiar troieni.

  2. Cristi Cluj

    sa inteleg ca daca folosesc avast free edition impreuna cu mallware bytes pro e suficient nu? ms frumos ptr raspuns in advans radu…

    1. happyday

      e o combinatie buna daca nu-ti incetineste sistemul 🙂

Leave a Reply