I'm working on a pC
that has this malware. It's one of those programs that pop up a fake
antivirus dialog and try to scare the user into either installing something, or
buying something that they shouldn't. Has anyone seen this particular
variant before? Nod32 isn't detecting it at all. I've seen
similar trojans in the past, and I was able to remove those using a little
utility called SmitfraudFix.exe; However, SmitfraudFix isn't detecting
this particular worm. The issue is further complicated by the fact that
this machine is offsite, and I'm trying to talk a user through fixing this over
the phone. I therefore really want to stay away from solutions that
require hand editing the registry if at all possible.
Thanks,
Al
Puzzuoli
Michigan State University
Resource Center for Persons with
Disabilities
120 Bessey Hall East Lansing, MI
48824-1033
517-884-1915