+ Post New Thread
Page 1 of 2 12 LastLast
Results 1 to 15 of 17
Internet Related/Filtering/Firewall Thread, Spoof AV site in Technical; Had a few students & staff come across this site: Personal Antivirus It is a fake antivirus site. Not sure ...
  1. #1

    TechMonkey's Avatar
    Join Date
    Dec 2005
    Location
    South East
    Posts
    3,317
    Thank Post
    226
    Thanked 426 Times in 309 Posts
    Rep Power
    171

    Exclamation Spoof AV site

    Had a few students & staff come across this site:
    Personal Antivirus
    It is a fake antivirus site. Not sure what payload or scam it is but I'm sure it isn't fun.

  2. #2
    rolfea's Avatar
    Join Date
    Nov 2008
    Location
    Hereford
    Posts
    682
    Thank Post
    66
    Thanked 50 Times in 25 Posts
    Rep Power
    22
    its easy to see how people would fall for that.

  3. #3

    TechMonkey's Avatar
    Join Date
    Dec 2005
    Location
    South East
    Posts
    3,317
    Thank Post
    226
    Thanked 426 Times in 309 Posts
    Rep Power
    171
    Definitely. It also has the classic dialogue boxes that guide you in no matter what you select.

  4. #4
    Andie's Avatar
    Join Date
    Sep 2006
    Location
    Cambridgeshire
    Posts
    802
    Thank Post
    167
    Thanked 66 Times in 49 Posts
    Rep Power
    30

    Unhappy Help! Personal Antivirus has installed itself!

    Teacher has just come to say her laptop is flashing up anti-virus warning messages. Get there to find a web page pretending to show that there are no end of trojans on all her disks, and a message box asking if we want to remove them. Trying to click cancel on this box just brings up a box asking to install Personal Anti-virus. No matter what i did with this box it kept trying to install program. Closed web page in end which then let me close all other windows. But too late - it looks like it had installed itself anyway. Teacher had just been browsing the Internet when all of a sudden all webpages disappeared and this antivirus stuff came up. Not the sort of teacher to do anything silly. We already have sophos on the laptop. There is now a desktop shortcut to something called Personal Antivirus, but the program is not listed when I go to the Add/Remove Programs list in Control Panel. The program is also now on the Start menu, and had an uninstall option in its Start menu folder, but that does nothing. There is also a button in the system tray on the taskbar. This is screaming messages about a critical file infection.

    I have just set sophos to scan the computer. If that doesn't find anything, does anyone know how to get rid of this????

  5. #5

    rush_tech's Avatar
    Join Date
    Jul 2006
    Location
    Nottingham
    Posts
    1,419
    Thank Post
    112
    Thanked 269 Times in 202 Posts
    Rep Power
    194
    Here's what I got
    Attached Images Attached Images

  6. #6

    Join Date
    Nov 2007
    Location
    Rotherham
    Posts
    1,679
    Thank Post
    122
    Thanked 126 Times in 102 Posts
    Rep Power
    46
    Depending on how nasty it is;
    • Disable system protection
    • look in the registry for random things staring up - HKLM\software\microsoft\windows\current version\run\ and check what everthing is on google.
    • Make a note of any dodgy files, find them and delete them (use task manager to terminate processes if necessary)
    • Delete registry keys


    editing the registry incorrectly can totally knacker your computer.

    It's a bit rough but it's a general principle. Software like AdAware and SpyBot can help as well.

  7. #7
    mrtechsystems's Avatar
    Join Date
    Jun 2005
    Location
    Yorkshire
    Posts
    425
    Thank Post
    105
    Thanked 22 Times in 22 Posts
    Rep Power
    26
    Yeah I have working on a machine today that tries to look like AVG

    Malware Bytes - to removed the problems

  8. #8
    SC-UK's Avatar
    Join Date
    Feb 2009
    Location
    London
    Posts
    569
    Thank Post
    36
    Thanked 85 Times in 71 Posts
    Rep Power
    30
    Good old Safari, here's what I get as well:
    Attached Images Attached Images

  9. #9

    FN-GM's Avatar
    Join Date
    Jun 2007
    Location
    UK
    Posts
    16,319
    Thank Post
    902
    Thanked 1,799 Times in 1,550 Posts
    Blog Entries
    12
    Rep Power
    466
    chrome gave me warning message. I have blocked the site anyway i doubt IE will stop it.

  10. #10
    gibbo_ap's Avatar
    Join Date
    Nov 2007
    Location
    Staffs, UK
    Posts
    937
    Thank Post
    233
    Thanked 81 Times in 64 Posts
    Rep Power
    37
    on anti virus 2009 i used wi sys restore worked a treat tho this one was a manual reg jobbie ah the fun!

  11. #11
    SC-UK's Avatar
    Join Date
    Feb 2009
    Location
    London
    Posts
    569
    Thank Post
    36
    Thanked 85 Times in 71 Posts
    Rep Power
    30
    Quote Originally Posted by FN-GM View Post
    chrome gave me warning message. I have blocked the site anyway i doubt IE will stop it.
    I have just tried it on W7 with IE8 and no warning message whatsoever! (Although I am not running any AV at the moment as it is a test VM)

  12. #12

    Join Date
    Jan 2007
    Location
    Durham, UK
    Posts
    328
    Thank Post
    33
    Thanked 17 Times in 12 Posts
    Rep Power
    21
    Quote Originally Posted by SC-UK View Post
    I have just tried it on W7 with IE8 and no warning message whatsoever! (Although I am not running any AV at the moment as it is a test VM)
    Probably because safari, firefox, chrome etc all do lookups to the google safe browsing database, whereas IE doesn't i dont think :P

  13. #13
    Andie's Avatar
    Join Date
    Sep 2006
    Location
    Cambridgeshire
    Posts
    802
    Thank Post
    167
    Thanked 66 Times in 49 Posts
    Rep Power
    30
    Sorry I didn't get back to this earlier. I got rid of the thing eventually. Although the uninstall didn't work from the Start Menu, it did work if I double clicked it directly from the Personal AV folder in Program Files. I also did a scan with sophos and deleted any references to Personal AV it found. Probably not the best way to do it though. I gave the laptop to my helpful secondary school backup team, and they scanned it for malware, etc. and found nothing. It looks like it was an aggressive program, hopefully not having done any major damage. Haven't had any further problems.

  14. #14
    Andie's Avatar
    Join Date
    Sep 2006
    Location
    Cambridgeshire
    Posts
    802
    Thank Post
    167
    Thanked 66 Times in 49 Posts
    Rep Power
    30
    I've had another machine attacked by a slightly different and more aggressive spoof AV. This one is called Personal Security. I have no idea what the teacher did to allow it on, if anything. Standalone laptop with fully updated Norton AV and Norton Internet Security running. Neither reported anything. Anyone know if this is a web based thing like Personal AV, and if so what the site is so I can ask Internet Provider to block? I'm going to do a search myself using Firefox, which seems a lot better at detecting and stopping this stuff.

  15. #15

    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    123
    Thank Post
    8
    Thanked 11 Times in 10 Posts
    Rep Power
    20
    I had a laptop with Personal security warning of virus. Could not do anything. Either access denied or when I tried to install malawarebytes it did nothing.
    Eventually found on a forum somewhere. "Go to C:\program files\common files\psecurity\ double click uninstall.exe"

    I could not believe that it would work but I thought I had nothing to loose and it did work.
    So I then installed malawarebytes and ran a scan which picked up a few bits that were left.

    Who ever heard of a virus with an un install

  16. Thanks to ianniow from:

    joe90bass (10th February 2010)



SHARE:
+ Post New Thread
Page 1 of 2 12 LastLast

Similar Threads

  1. [Video] Sherlock Holmes spoof
    By mattx in forum Jokes/Interweb Things
    Replies: 0
    Last Post: 7th April 2009, 01:25 PM
  2. Is this a spoof email
    By cromertech in forum MIS Systems
    Replies: 8
    Last Post: 1st April 2009, 02:55 PM
  3. [Video] Ross Kemp On Gangs Spoof
    By Little-Miss in forum Jokes/Interweb Things
    Replies: 1
    Last Post: 18th December 2008, 09:46 PM
  4. awesome nike football ad spoof
    By browolf in forum Jokes/Interweb Things
    Replies: 5
    Last Post: 1st June 2006, 01:04 PM
  5. Nice spoof t-shirts.
    By Dos_Box in forum Jokes/Interweb Things
    Replies: 0
    Last Post: 12th September 2005, 11:23 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •