The other week a customer called us and asked for our assistance, they said that they had click on something in an email and that their computer has been acting strange ever since!
Upon further investigation we discovered that the person click on an attachment in an email that they received from UPS. The attachment was a zip file that harbored a malicious software script that immediately infected her computer. The malicious software was reporting multiple infections on her workstation and asking her click on another link to fix the problem. Fortunately the person was smart enough to turn off the computer and give us a call. Had he/she followed thru, they would have been asked for their credit card to purchase a piece of software that would remove the infections.
This infection is known as AntiVirus 2009.
Antivirus 2009 is a new rogue anti-spyware program. It is also a clone of Antivirus 2008 – also a rogue, and one that’s produced more clones than any other recently. The list of these clones is long: System Antivirus 2008, Ultimate Antivirus 2008, Vista Antivirus 2008, XP Antivirus 2008 etc.
Like any other of it’s predecessors, Antivirus2009 uses trojans, such as Zlob or Vundo, to spread. These trojans lurk in porn/warez websites disguised as video codecs, and, upon entering the system, floods the user with popups and fake system notifications, supposedly to inform him of an infection. While the system at hand may indeed be infected, Antivirus 2009 will inform the user of this regardless of whether it’s true or not. The point of this disinformation is to convince the user he is infected and therefore needs an antispyware program to dispose of the threat. The user might click on one of the popups or notifications, all of which claim they will take him to a legitimate security tool, but try to make him purchase Antivirus2009′s “licensed version” instead. Antivirus2009 may redirect web browser to antivirus-premium-scan.com, webscannertools.com, googlescanners-360.com, livesecurityinfo.com, antivirusonlivescan.com, bestantivirusscan.com, antivirus-best.com, internetquarantinesite.com, premiumlivescan.com and secureclick1.com websites that sell the malware. Some of these website are not only fraudulent, but they are also malicious. they are capable of installing additional malwares.
Antivirus 2009 is a scam and should be treated as such: do NOT download or buy it and block it’s websites using your HOSTS file: Webscannertools.com
Here is what it looks like 
If you search the WEB you will find many solutions that say it can be fixed, but the truth is the only way to recover 100% from this backup your data and re install windows and all of your applications. This is a time consuming project and can take anywhere from 2 to 4 hours for a professional to complete.
So the real cost of spam is 2 to 4 hours of labor and no computer for a day or two.
The cost of prevention is always less that the cost or the repair!
Want to prevent this sort of thing, call or email me at 604-925-8106 x2 or peter@acsl.ca
