Help - Search - Members - Calendar
Full Version: The secret recipe for Antivirus XP Pro
BleepingComputer.com > General Topics > News
   
Grinler
Vundo uses a formula of constant security warnings, desktop hijackings, and Internet Explorer hijackings to foist Antivirus XP Pro on to your computer. Recent installs of Vundo have been showing an increasing amount of advertisements for Antivirus XP Pro, so we should expect to see quite a few computers infected with this malware.

The formula consists of a healthy dose of Internet Explorer hijackings:



Internet Explorer Hijack #1 advertising Antivirus XP Pro
Internet Explorer Hijack #1 advertising Antivirus XP Pro



Internet Explorer Hijack #2
Another Internet Explorer Hijack

Add a dose of fake security warning:

Fake Security Warning
Fake Security Warning

A sprinkle of desktop hijacking:

Desktop Hijacking
Desktop Hijacking
 

Finally, stir a little Vundo to glue it all together in, and you have Antivirus XP Pro.




Antivirus XP Pro
Antivirus XP Pro
 

Unfortunately, Google Trends data corroborates what I am seeing as shown by the graph below. This graph shows a recent increase of activity for the search keyword Antivirus XP Pro.

 

Google Trends graph for the keyword Antivirus XP Pro
Google Trends graph for the keyword Antivirus XP Pro


So, if you are one of the unlucky ones who has Antivirus XP Pro installed, please ignore the warnings, and instead use the guide linked to below to remove it for free.

 

Zachary09
Hey thanks for putting this up my friend got this program and it has really screwed up his computer.
pochp
I have written about these 'scarewares' but maybe not here.
Surfrunner
I have the black warning screen and fake security button (pic 3 & 4) as shown on your page, I don't seem to have AntivirusXP on my computer.. What else can it be and how do I get rid of it. Right now it seems to disable Malewarebytes program, so I can't run that.. Help!!!
m0le
Hi Surfrunner,

I suggest you click this link to the Am I Infected forum for some confirmation of what you have.

Link
o_rly
I found this on my VM, but it didn't have the black background.
fardin100
Hi, Thanks again for this great post admin! It is nice of you to teach others about this infection and teach them to remove it. thumbup.gif
fatih_ictuzer
thnak you
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.