Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Changing face of Fast Antivirus 2009?


  • Please log in to reply
No replies to this topic

#1 seaspine

seaspine

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 18 August 2009 - 12:12 AM

When I sat down at a computer at work today and accessed our online portal where we transfer company information, there was a pop up from Fast Antivirus 2009. I already knew this was a rogue. Closed out and ran MBAM. It found not just an annoying few files but 611 registry entries,files and over 500 Security.Hijack entries. The .exe file was located but is now called EX4677.exe-0 17A09AB.pf located in Prefetch and another called simply EX4677 in AppData. Cleared it out through 3 full MBAM scans and then ran HijackThis. Deleted BHO's and associated remnants. Just thought I'd post this as some of the online forums/blogs were incredibly weak (not this one) and misleading as to how much it had penetrated our company's computer. Obviously my main concern at this point is the amount of information that left. If you want, I'll post my first page of malewarebytes and my HijackThis pre and post so you can get an idea how nasty this little thing can be.

Edited by garmanma, 18 August 2009 - 07:41 AM.
Moved to more apprppriate forum


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users