Reply
Super Spam Squasher
Bombastus
Posts: 1,686
Registered: ‎11-16-2009

Re: Antispyware soft infection

I think all anti-virus program are, quite frankly, real bad at detecting and removing rogues. Norton is definitely not alone in this regard. I have tested rogues on several systems, with Norton, Kaspersky and Avira, and rogues slip past them all quite easily. The only way at the moment to make sure they don't install is using some kind of anti-executable, only allowing white-listen files to run by default. Unfortunately, Kaspersky is the only of the above that uses this; with that enabled, it stopped everything I threw at it. This also decreases user friendliness, of course, since it will block non-ware as well if it is not recognized on the white list. Still, I wish Norton implemented some kind of this type of anti-executable; Sonar and Download Insight are both great, but as we can see from the number of infections reported here and otherwise, they are not bulletproof.
Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Antispyware soft infection

I managed to find a installer for the Rogue "Antispyware Soft" 

 

By VirusTotal  Symantec detects it as "Trojan.FakeAV" although that seems a bit of a generic FakeAV detection 

 

In saying that, I was able to unpack the installer onto my Desktop without "Auto-Protect" detecting the file before someone could run the file,

 

Quads

Visitor
drexxell
Posts: 2
Registered: ‎05-17-2010

Re: Antispyware soft infection

 


floplot wrote:

Hello

 

These are rogue antivirus programs that are not all the same viruses. 


 

According to this entry, they are the same...and clearly the M.O. of each infection has been the

same, so I imagine they all exploited the same weakness that Norton continues to not protect.

 

http://en.wikipedia.org/wiki/MS_Antivirus_%28malware%29

 

 

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Antispyware soft infection

 


drexxell wrote:

 


floplot wrote:

Hello

 

These are rogue antivirus programs that are not all the same viruses. 


 

According to this entry, they are the same...and clearly the M.O. of each infection has been the

same, so I imagine they all exploited the same weakness that Norton continues to not protect.

 

http://en.wikipedia.org/wiki/MS_Antivirus_%28malware%29

 

 


 

Wikipedia pages are just written by who ever wanted to type the info out.

 

I can tell you that they are not all the same,  there are more than one family listed there so the removal procedure  is different as well, Then there are the different detections required.

 

Quads

 

 

Newbie
Spencer52
Posts: 1
Registered: ‎05-20-2010

Re: Antispyware soft infection

@ richj44  I had the same exact problem and experienced the same thing, however, I decided to try again the next day.  Norton Antivirus detected the virus immediately and removed the fake Antivirus Spyware within 3 minutes.  Norton is great, but sometimes you have to give it time to recognize the threat which can also be considered a flaw depending how malicious the invading virus may be.

Visitor
melissaslater
Posts: 3
Registered: ‎06-04-2010

Re: Antispyware soft infection

HELP!!!!!!  i also have antispyware soft attacking me... however i can not log on-line to download these "other" programs to find the virus.....  i am in SAFE mode but i have no internet connection???  aaahhhhhhh....trapped!!!  what to do!!?????!! i know i'm connected because my other computers are live and when i go back to regular mode all the porn sites start popping up...... what to do???

 

someone please help me....although i am one my computers at least 6 hours a day (i'm a digital photographer)  i am not knowledgeable with the innerworkings... i need major help!  i thought Symantec  was protecting me... but guess not :(.. can anyone out there who knows lend me some layman's advise??,..... please.......::smileysurprised:

Super Keylogger Crusher
mattsegers
Posts: 452
Registered: ‎01-18-2009

Re: Antispyware soft infection


melissaslater wrote:

HELP!!!!!!  i also have antispyware soft attacking me... however i can not log on-line to download these "other" programs to find the virus.....  i am in SAFE mode but i have no internet connection???  aaahhhhhhh....trapped!!!  what to do!!?????!! i know i'm connected because my other computers are live and when i go back to regular mode all the porn sites start popping up...... what to do???

 

someone please help me....although i am one my computers at least 6 hours a day (i'm a digital photographer)  i am not knowledgeable with the innerworkings... i need major help!  i thought Symantec  was protecting me... but guess not :(.. can anyone out there who knows lend me some layman's advise??,..... please.......::smileysurprised:


Instead of choosing "Safe Mode" chose "Safe Mode with Networking" and see if you have internet connectivity? You could also use a seperate machine to download the other programs and then use a flash drive, cd or simply transfer them via LAN (although I don't recommend that, as the other pc(s) might become infected).

 

You could also try Norton Power Eraser.

 

Matt

"The fact that man knows right from wrong proves his intellectual superiority to other creatures; but the fact that he can do wrong proves his moral inferiority to any creature that cannot."
- Mark Twain
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Antispyware soft infection

Please see this post by mdturner for more information.

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Virus-cut-internet-access-amp-exe-s-f...

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Visitor
melissaslater
Posts: 3
Registered: ‎06-04-2010

Re: Antispyware soft infection

thank you!  thank you!  thank you!  worked like a charm... i'm de-fecting now..... my God bless you and your computer! :)!

Super Keylogger Crusher
mattsegers
Posts: 452
Registered: ‎01-18-2009

Re: Antispyware soft infection

Pleasure :-) glad to hear it worked:-)

 

Could you do us a favour though, and (I'm assuming you are doing a scan with MBAM) under the logs tab, could you please attach the log to this thread? :-) Use the attachment bar at the bottom of the text-area when you are creating a new message :-)

 

Thanks!!! :-)

 

Matt

"The fact that man knows right from wrong proves his intellectual superiority to other creatures; but the fact that he can do wrong proves his moral inferiority to any creature that cannot."
- Mark Twain