Re: VirusBursters - How Does it Get Installed?



Paul Adare wrote:


Thanks Malke, I'll mention that to them.

Any other vectors that anyone is aware of?

Tons. Unfortunately, there are many ways. Often it is as simple as they
are already infected and the malware is busy downloading more malware,
which is busy downloading more malware.... ad infinitum or until the
computer locks up completely. You can see a good illustration of that
on Ben Edelman's site - http://www.benedelman.org/.

Another way is the classic popup that comes when the user is surfing and
it says something alarming like "Your computer is not safe! Download
[insert malware program here] and protect yourself!" So the poor chump
clicks on it and before s/he knows it, they've got Smitfraud or a Vundo
(Winantivirus, Spyfalcon, etc.). The VirusBursters crap is another
variant of the Smitfraud trojan.

There are a lot of "Safe Hex" sites for you to point your daughter and
her S.O. to, but this one is quite good and aimed at regular users:
http://www.getsafeonline.org/

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
.



Relevant Pages

  • Re: Program Startup Problems
    ... usually say much about "malware" or "safe hex", even if that turns out to be ... That Subject line says nothing about malware, ... It took me only a few minutes to scan these headers and find the responses, ... Nigel, and I could find dozens more in less than an hour, I'm sure. ...
    (microsoft.public.windowsxp.general)
  • Re: Best procedure to run anti-virus scan?
    ... | Save a log of what's happened and if malware ... Anti Malware will find them hidden or not. ... | Needed for "safe hex", along with "Do NOT hide file name extensions". ... | May not be able to resolve per-account settings. ...
    (microsoft.public.security.virus)
  • Re: spyware
    ... | It sounds as though you have a version of the Smitfraud virus. ... | through the following malware removal steps: ... | find the *.html malware file and delete it. ... If it is a Smitfraud Trojan, I have created a specific script that removes the Trojan and ...
    (microsoft.public.windowsxp.general)
  • Re: Web site blocked
    ... "Malware program" that recognized it as spyware. ... Review the "Safe Hex" information at these sites and do a thorough ...
    (microsoft.public.windowsxp.general)