<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tech blog &#187; Threats</title>
	<atom:link href="http://www.chrismadge.com/tech/category/threats/feed" rel="self" type="application/rss+xml" />
	<link>http://www.chrismadge.com/tech</link>
	<description></description>
	<lastBuildDate>Mon, 21 Jun 2010 19:15:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>FakeAV makes a comeback</title>
		<link>http://www.chrismadge.com/tech/fakeav-makes-a-comeback</link>
		<comments>http://www.chrismadge.com/tech/fakeav-makes-a-comeback#comments</comments>
		<pubDate>Tue, 01 Dec 2009 23:48:29 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Remediation]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=94</guid>
		<description><![CDATA[In 2008, across my clients I saw a lot of cases of Windows Antvirus Pro 2008 variants&#8230; Towards the end of the year and through most of 2009 I didn&#8217;t see a lot of infections. However, it looks like it has regrouped and come back in full force. I&#8217;m seeing an escalating number of FAKEAV [...]]]></description>
			<content:encoded><![CDATA[<p>In 2008, across my clients I saw a lot of cases of Windows Antvirus Pro 2008 variants&#8230; Towards the end of the year and through most of 2009 I didn&#8217;t see a lot of infections. However, it looks like it has regrouped and come back in full force. I&#8217;m seeing an escalating number of <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakeavajh.html?_log_from=rss" target="_blank">FAKEAV</a> infections with my clients. I&#8217;m still investigating on how the infections got there because the users stretch across a lot of different roles &#8230; developers, merchandisers and accountants. Unfortunately, Web history and Installed Application hasn&#8217;t been a help.</p>
<p>I do know however have a remediation plan.</p>
<p>Step 1. Download Combofix from a reputable source on a clean working workstation</p>
<p>Step 2.  Copy the combofix executable to a USB drive.</p>
<p>Step 3.  Reboot the workstation and load Windows in Safe Command Prompt Mode</p>
<p>Step 4. Run the Combofix Executable off the USB drive</p>
<p>Step 5. Let the Computer reboot and Combofix to complete.</p>
<p>Step 6. Use an Antivirus client other than TrendMicro (as it won&#8217;t see the virus&#8230; it&#8217;s useless I know) to complete a scan on the remdiated workstation. It should come up with an all clear.</p>
<p>Step 7. Return the workstation back to the enduser.</p>
<p>On the variant that is out right now this remediation path has been very successful for me. I hope it is for you..</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/fakeav-makes-a-comeback/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
