View Full Version : Winantivirus - Suspicious
Albinoni
July 21st, 2006, 11:31 PM
My Father was using his PC and this pop up came up telling him to install this software called winantivirus by Winsoftware. I've never heard of this AV software, who makes it and whats it like. I've already got Bitdefender Pro 9 running on his PC for him, so really he doesnt need stuff like this. I just hope this so called winantivirus is not spyware.
colt45allstar
July 21st, 2006, 11:37 PM
Winantivirus is bad news.
It's indeed malware of some form and not usable antivirus software in the least.
Assuming it got on his computer, you might want to help him find removal instructions.
Yahoo or Google would likely have helpful links.
Blackspear
July 21st, 2006, 11:41 PM
I suspect he has Vundo (http://www.castlecops.com/postx119486-0-0.html) and the more I look the more it confirms this. (http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=16923#M16923)
Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
1 Reboot your PC into "Safe Mode".
2. Double click on VundoFix.exe
3. Place a tick next to "Run VundoFix" as a task.
4. You will receive a message saying VundoFix will close and re-open in a minute or less.
5. Click "OK".
6. When VundoFix re-opens, click the "Scan for Vundo" button.
7. Once it's done scanning, click the "Remove Vundo" button.
8. You will receive a prompt asking if you want to remove the files, click "Yes".
9. Once you click yes, your desktop will go blank as it starts removing Vundo.
10. When completed, it will prompt that it will shutdown your computer, click "Ok".
11. Turn on your computer.
Let us know how you go...
Cheers ;D
Marcos
July 22nd, 2006, 08:08 AM
Or maybe his computer is infected with the Zlob trojan. It also downloads "badware" like this which pretends that your computer is infected, and lures you into buying it in order to be able to remove the downloader that actually downloaded the software.
betauser2
July 22nd, 2006, 08:11 AM
hxxp://www.winantivirus.com/ is this what your referring to?
altered url==bigc
Albinoni
July 22nd, 2006, 08:16 AM
-{ Quote: "Or maybe his computer is infected with the Zlob trojan. It also downloads "badware" like this which pretends that your computer is infected, and lures you into buying it in order to be able to remove the downloader that actually downloaded the software." }-
Yes your correct if I recall now I did see BD pop up blocking this Zlob Trojan.
Albinoni
July 22nd, 2006, 08:18 AM
I actually ran a scan with both BD Pro 9 and also Spybot S&D and BD found and deleted two viruses while Spybot also picked up 4 Trojans and I'm sure one of them was the Zlob one.
TOMxEU
July 22nd, 2006, 10:17 AM
http://img124.imageshack.us/img124/8121/capture07222006161327en7.jpg
betauser2
July 22nd, 2006, 10:34 AM
cheers BigC
dog
July 22nd, 2006, 11:42 AM
~Please~ no more links ... it's a rogue AV ... Whether sarcastic or not ... some less knowledgeable member/guest could DL the product - which no one would want. ;)
Thanks in advance for everyones understand and cooperation. :)
Steve
Albinoni
July 26th, 2006, 10:57 AM
-{ Quote: "I suspect he has Vundo (http://www.castlecops.com/postx119486-0-0.html) and the more I look the more it confirms this. (http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=16923#M16923)
Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
1 Reboot your PC into "Safe Mode".
2. Double click on VundoFix.exe
3. Place a tick next to "Run VundoFix" as a task.
4. You will receive a message saying VundoFix will close and re-open in a minute or less.
5. Click "OK".
6. When VundoFix re-opens, click the "Scan for Vundo" button.
7. Once it's done scanning, click the "Remove Vundo" button.
8. You will receive a prompt asking if you want to remove the files, click "Yes".
9. Once you click yes, your desktop will go blank as it starts removing Vundo.
10. When completed, it will prompt that it will shutdown your computer, click "Ok".
11. Turn on your computer.
Let us know how you go...
Cheers ;D" }-
Many kind thx for your help here but I'm just wondering why doesn't Bitdefender get rid of this since its one of the best av software around.
The other thing is I ran a scan using Spybot S&D and after the scan it did pick up the Winantivirus but after I clicked on fix problem button thinking and hoping that I got rid of it, guess what ? it came back, i.e it just seems to come back.
Albinoni
July 26th, 2006, 10:59 AM
-{ Quote: "hxxp://www.winantivirus.com/ is this what your referring to?
altered url==bigc" }-
Yes thats correct.
Blackspear
July 26th, 2006, 10:12 PM
-{ Quote: "Many kind thx for your help here" }-My pleasure ;D
-{ Quote: "…I'm just wondering why doesn't Bitdefender get rid of this since its one of the best av software around." }-I guess it would depend upon the settings used. Once infected with this particular nasty you have to follow specific instructions to the letter in order to remove it.
-{ Quote: "The other thing is I ran a scan using Spybot S&D and after the scan it did pick up the Winantivirus but after I clicked on fix problem button thinking and hoping that I got rid of it, guess what ? it came back, i.e it just seems to come back." }-See the above answer.
Cheers ;D
Arin
July 30th, 2006, 12:44 PM
Symantec products remove it properly.
ASpace
July 30th, 2006, 02:35 PM
-{ Quote: "Symantec products remove it properly." }-
Thanks for the information
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums