Macro Antivirus 2009 / Smart Antivirus 2009 / Anti Virus Pro 2010Free Porn! Fake Security Alerts, Fake Virus Scans- read How to Avoid/Fix this Sept 08/ Sept 2009 spyware/trojan)

image from:
Bharath's Security Blog, the post was on June 28th 2008, notice the fake scanning and detection. FAKE!)
Symptoms:
1. icons of a sexy lady licking on the desktop with links to
Free Porn! (wow!)
2. pop-ups of fake Malware alert. best thing was, it looked pretty close to windows defender.
3. icons in the shape of window's Armour icon for security alert, both in taskbar and on your desktop with rainbow colors.
4. fake Security Alert on 'virus detected' with a yes or no, both of which leads you to download
5. yunze**.exe or anti virus pro 2009.exe tasks running which launches up to 5 windows sequentially(sounded chinese)
6. Big pop up of Fake virus scanning as similar to above called 'Macro AV 2009'
First Detected:
dated around June-Sept 2008
1st version: Antivirus 2009 - late june 2008
2nd version: Smart Antivirus 2009 - first week of sept 2008
3rd version: Macro Antivirus 2009 - 2nd week sept 2008
New version: Anti-Virus Pro 2010 - 3rd Week sept 2009
this guy had the same issue as posted in 26 June 08 with the
same virus scanning stimulation. It was the first version. mine was the 3rd possible variant with the name 'Micro AV 2009' on 11th Sept 08.
and here's the 2nd variation detected on 2nd Sept 2008 with the word 'Smart Antivirus 2008' and
how to remove it, the report has ALL the pop-up windows you'll see when you're infected.
its smart. it changes names & looks frequently.First Steps: Closing the pop-ups1. Do not click on any of the pop-ups. you can move them aside but do not click or try to close.
2. Go to (ctrl+shift+esc to launch
task manager > in process section, there would be 4 processes named 'Yunze**.exe' or possibly, AV2009.exe / any-other-name.exe running. just look for any single executable with .exe
its not listed in the programs section.
3. Right-click > End process -- it will close all the pop-ups and won't appear anymore.
4. Start > Run > type MSCONFIG > go to Startup > uncheck Anti Virus Pro 2009
5. download the following to remove:
Microsoft Malicious Removal - first step after turning the ads off.
Malwarebytes Malware Remover, free version - Let's clean up. highly recommended. removes it very easily.
Microsoft Defender - for prevention of future occurances.
note: deleting the folder created in C:\windows\micro AV 2009 does NOT work. it rebuilts itself. removing the registry doesn't work after "anti virus 2010"
Only running a full system scan with a Malware remover tool or a full-reinstallation of the OS works.Possible incident for issue to occur:
Users are prompted to install 'Add-Ons' for IE / Firefox inorder to proceed with browsing or playing of music or downloading a file.
instead of downloading authentic softwares, it auto-installs itself.
1. installed 'GetBot' which manages downloads and allows resume and pause functions.
2. installed some other 'true downloader' which was supposed to manage downloads.
3. installed a chinese website 'browser downloader' aid for IE & firefox as an add-on.
The last resort if all above do not work - removal situation:1. moved data in affected drive, e.g. D:\ to a portable disk.
2. format partition D:\
3. installed vista or XP fresh on D:\ drive.
OR
5. restore image to partition C:, overwriting the affected OS.
Recommend Self-Defense Softwares:Also, make sure you're equipped with
1.
Windows Defender2. Antivirus software - e.g. freeware
Panda Antivirus 20083. Mcafee - get
McAfee, its not invasive, doesn't slow the system on boot.
4.
Kaspersky Anti-virus. its very very good. you can download it for a trial use. its very good in detecting spywares and trojans and bad cookies.
5. Symantec Antivirus. tends of lags the boot-up process and slows the system everytime it scans.
more reads:
A New Rouge @ Readers Zone, Sept 08A new Rouge @ Offensive ComputingAnother new variant to avoid @ MicrosoftMVPsHow to remove Smart AV 2009 @ Bleeping ComputerFake Malware Protecter 2008 Lies! @ Bill Mullins WeblogAntivirus 2009 Alert @ Bharath's blogspotHow to kill spyware processes