My user has supplied a screenshot of fake AV in the wild. I never could get it to show up for myself but she did last night while my wife and I were at a movie. Attached screenshot.
I have found a website that may be talking about a variant of this or just a renamed same thing. It does look and sound very similar. They are offering a cleaner for this. I won't be using it until I get some confirmation that it would be safe.http://www.2-viruses.com/remove-win-7-antispyware-2010
Update 1: I didn't find any services or entries that were part of the manual removal instructions from the above url.
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1?
None of these present. It doesn't mean that they don't get recreated somehow.
Update 2: After I got Microsoft Security Essentials to finally finish, It found Java:Selace K,N and O. http://www.microsoft.com/security/portal/T...px?query=selace
It quarantined and stopped them all. Then I deleted them from quarantine. MS says this is a serious virus that takes advantage of a Java exploit. I keep my users' Java reasonably updated but cannot keep them up to the day updated or control what sites they visit. So we have these types of problems rarely but periodically about 1 every 1 or 2 months. I did also end up uninstalling the MyHeritage toolbar. Funny thing about that, the MyHeritage toolbar uninstalled did not show up in the Programs uninstall on Windows 7 until about a half hour ago or maybe I never thought to look there. It definately was not showing up in the Program Files folders where it should have. I will let the machine ride for now and not rebuild like I thought I would have to. --M
Edited by mldennis, 28 February 2010 - 09:11 PM.