Archive for August, 2006

VirusBurst bursts onto the scene as the latest rogue anti-spyware app.

I keep a close eye on the various infector files that install the many rogue anti-spyware applications that are on the market and recently there has been a lull in new releases. Where before a new infector would be released almost daily, it has been a couple of weeks since a new variant has been released. Why? Because our good friends at:

Burst Technology GesmbH
Judi Stewart (judi.stewart@gmail.com)
Davidgasse 87
Vienna
null,A-1100
AT
Tel. +431.3365073

have been designing a new variant called VirusBurst.

VirusBurst Screen
VirusBurst Screen

Don’t let the name fool you, though, this is just the same old rogue anti-spyware wrapped into a new disguise. VirusBurst is also from the same makers of SpywareQuake, SpyFalcon, SpyAxe, SpywareStrike, etc, etc.

This latest incarnation currently uses the C:\Windows\System32\eowygj.dll file to infect you. Once loaded it will download VirusBurst and install the software without permission while displaying fake security alerts like the one shown below. VirusBurst’s security alert contains the text “System detected virus activities. They may cause critical system failure. Please, use antimalware software to clean and protect your system from parasite programs. Click this baloon to get all available software.” When you click on this fake alert it will bring you to hxxp://www.virusburst.com/?aff=321.

One of the things I find most amusing about these programs are that they detect the file that is used to download and install it as a Trojan. Take a look at the above screen shot of VirusBurst. Notice how it detects C:\Windows\System32\eowygj.dll and says it’s a trojan. Talk about deceptive tactics huh?

Fake VirusBurst Security Alert
Fake Security Alert from VirusBurst

By tomorrow the various rogue anti-spyware removers will be updated to remove this variant. Until these tools are updated, though, we have put together a removal guide which can be found here:

How To Remove VirusBurst (removal Instructions)

Tags: No Tags

Comments (4)

Kaspersky Anti-Virus: Free Online Virus Scanner

Kaspersky has released an announcement that on August 8th, 2006 they have updated the software used for the Kaspersky Anti-Virus: Free Online Virus Scanner. In order to continue using the online scanner you will need to uninstall the old version it from your Add or Remove Programs list and then install the latest version. To do this you can follow these steps:

  1. Print out these instructions.
  2. Close all Internet Explorer windows.
  3. Click on Start and then Control Panel.
  4. Double-click on the Add or Remove Programs icon.
  5. Scroll through the list until you see the Kaspersky On-line Scanner entry and click once on it to select it.
  6. Now click on the Remove button.
  7. Click on Yes when it asks

The software should now be uninstalled from your computer.

To start using the new version go to the Kaspersky Anti-Virus: Free Online Virus Scanner page and click on the Kaspersky Online Scanner button and it should prompt you to install the new version.

Tags: No Tags

Comments (1)


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides


© 2003-2008 All Rights Reserved Bleeping Computer LLC.

Featured Microsoft Expert Zone Community