The Download Blog

Read all 'antimalware' posts in The Download Blog
December 4, 2009 6:13 PM PST

PC Tools Internet Security 2010 reviewed

by Seth Rosenblatt
  • 14 comments

PC Tools' Internet Security suite for 2010 gets some things right, and frustratingly drops the ball on others. It's hard not to like the feature set, which is robust, and the recent efficacy badge from Virus Bulletin. However, some of the problems in the suite are glaring and will potentially scare aware users who might otherwise find it a good security tool.

The default landing page should appeal to those who like quick glances to ensure everything is running smoothly. Green checkmarks or red Xes make it easy to see if you're at risk. Drilling deeper down to the settings pages could be better, though. Too often, the plain text felt squished by the chunks of white space on the right, and made it unnecessarily hard to parse logs and fine-tuning controls like the firewall or advanced scan settings.

The performance benchmarks weren't horrible, but they didn't impress, either. Falling somewhere in the middle of its competitors, and notably slow especially on computer start-up times, the suite could be much more nimble. Also annoying is that when held up against most of its competitors, the trial version is noticeably hamstrung. You only get 15 days to make a decision with the suite, and it won't remove any threats it detects.

What PC Tools fans will like is that although two earlier tests by Virus Bulletin this year gave PC Tools Internet Security 2009 failing marks, the first test of the new version passed the test on Windows 7. So for those with new computers, PC Tools' slightly lower price point of $50 for three licenses for its premium product may stand out as a good deal. Read the full review at CNET Reviews.

October 29, 2009 5:30 PM PDT

IOBit 360 refreshed for Windows 7

by Seth Rosenblatt
  • 9 comments

IOBit 360 is a relative newcomer on the antimalware scene, although the Chinese publisher is known for making solid utility software such as Smart Defrag. It's a fast and welterweight freeware utility for detecting and removing malware, and plugging your system's security holes before they can been exploited. The new improvements in version 1.10 include integration with the Windows 7 security center, a new feature that creates a USB key-portable version, a toolbar, and scan engine tweaks.

IOBit 360

(Credit: Screenshot by Seth Rosenblatt/CNET)

If you're unfamiliar with the program, it's fairly simple to figure out and use. The interface has large left navigation icons with simple labels that won't confuse novices, while the tools menu offers some useful features that more advanced users are sure to appreciate.

The Overview tab is the main window and it contains links for immediate Smart scans, definition file updates, a "security analysis"--which evaluates potential exploits in your system and includes Windows security patches--and a status update window. This tells you whether your real-time protection, automatic scans and updates, and heuristic-based scans are on or off. Automatic scans and updates, and scheduled scans, are restricted to the paid upgrade, which is currently being offered on sale for $19.95. It's usually $29.95.

The Scan tab lets you initiate a Smart scan, a Full scan, or a Custom scan, and the Protection tab lets you toggle your real-time protection status. It seems a bit odd that a user would want the separate controls that the program offers for "known malware" and "unknown threats," but you can toggle them independently.

A running scan that wound up taking about six minutes to finish.

(Credit: Screenshot by Seth Rosenblatt/CNET)

The Tools tab is what makes IOBit 360 comparable to others in its class, giving you seven useful system security tools. There's a Hijack scan for power users, a Security Holes scan, a Passive Defense that disables cookies in Firefox and Internet Explorer, and ActiveX in IE, and an Unlock and Delete tool for getting rid of files your system thinks are in use. This feature is slightly less important in Windows 7, which will tell you when you encounter a locked file where it lives, but the unlocking and deletion features are definitely useful.

There's a Privacy Sweeper that will clean not just cookies and cache but saved forms, download history, and other Internet traces in all the major browsers it detected on my system, including Firefox, Internet Explorer, Google Chrome, Opera, and Safari, but the sweeper will also check utilities such as archival tools, multimedia players, and other applications that regularly ping the Internet. These days, that's nearly everything.

Annoyingly, the PC Tuneup option takes you to the download page for another IOBit program, but users on the go will like that you can create a custom portable version, launchable from a USB key. IOBit 360 eats about 50MB of RAM when idle, with a Smart scan taking about 6 minutes and a full scan finishing in 45 minutes, making this one of the fastest in its class. I didn't notice any system lags while running it, and it didn't detect any malware on my system, although it did point out tracking cookies from multiple browsers. Third-party efficacy tests haven't yet been performed against high-performing competitors such as Ad-Aware or Malwarebytes, but IOBit is proving that the antimalware tool without antivirus isn't dead--yet.


October 13, 2009 12:18 PM PDT

AVG LinkScanner can detect malicious short URLs

by Lance Whitney
  • 6 comments

URL shorteners may be handy for your tweets on Twitter. But they're also known security holes since they don't display the actual address of your destination. A free tool from security vendor AVG may provide a solution.

AVG has updated its free LinkScanner tool to detect malicious pages hiding behind shortened URLs. The company said the tool checks the actual destination of each URL link to make sure the page is legitimate.

More than a dozen URL-shortening services abound on the Net, including TinyURL and Bitly. With its 140-character limit, Twitter automatically shortens URLs in each tweet via Bitly. Other services like WordPress also include a built-in URL shortener.

But Web browsers don't display the true address of a shortened URL, so you have no idea whether or not the destination page is safe. Hackers have easily been able to use the obscure nature of shortened URLs to conceal hazardous Web pages behind them.

"The problem with shortened links is that they usually don't bear any resemblance to the original URLs, which means that users don't always know what they're clicking," said Roger Thompson, chief research officer at AVG Technologies. "People click with the intention of going to a specific site, but the link can be easily hacked to send people to a site containing Trojans, spyware, rootkits, and other malware instead."

AVG, formerly known as Grisoft, bought LinkScanner in late 2007 as part of a larger acquisition. The tool has already proven helpful to Web surfers by analyzing Web pages behind each link that is either clicked on or typed into the browser.

Other solutions do exist to reveal the truth behind a short URL. The Web site LongURL can display the long version of a short URL. A Firefox plug-in called LongURL Mobile Expander can also translate from short to long.

But according to AVG, LinkScanner is now the only security tool on the market that can find poisoned Web pages behind a short URL. The company says it does not rely on blacklists and instead checks each link in real time.

Originally posted at Security
Lance Whitney wears a few different technology hats--journalist, Web developer, and software trainer. He's a contributing editor for Microsoft TechNet Magazine and writes for other computer publications and Web sites. You can follow Lance on Twitter at @lancewhit. Lance is a member of the CNET Blog Network, and he is not an employee of CNET.
September 29, 2009 9:01 AM PDT

Security Essentials graduates to v1.0

by Seth Rosenblatt
  • 66 comments

Microsoft has released version 1.0 of Security Essentials, the successor to Live OneCare. Originally known as Morro, Security Essentials retains the core features of OneCare, but abandons the additional heft of a firewall, performance tuning, and backup and restore options in exchange for making the program free. Rather than taking aim at full-featured security suites made by Symantec or Eset, the features available in Security Essentials indicate that Microsoft is aiming to compete with basic-but-free security apps.

For the select 75,000 public beta testers who got their hands on the program when the limited public beta was offered in June, there will be few appreciable differences between the beta and the final version. For the rest of the planet, Security Essentials features key defenses that are boilerplate for any respectable security program.

Features

It uses both definition file and real-time defenses against viruses and spyware, and also offers rootkit protection. The program's reputation-based detection and software signature-based detection seem to rely heavily on Microsoft SpyNet, the unfortunately named cloud-based service that compares file behavior across computers running various Microsoft operating systems.

The official version 1.0 of Microsoft Security Essentials looks identical to the popular limited beta version from June 2009.

(Credit: Screenshot by Seth Rosenblatt/CNET)

SpyNet was introduced in Windows Vista and extended to Windows 7, but Microsoft Security Essentials is the only way to access the network on Windows XP. Unlike other security vendors that allow customers to take advantage of the benefits of their behavioral detection engines while opting out of submitting information, there's no way to do that with SpyNet.

You can choose between two SpyNet memberships. Basic submits to Microsoft the detected software's origins, your response to it, and whether that action was successful, while the Advanced membership submits all that plus the location on your hard drive of the software in question, how it operates, and how it has impacted your computer. Both basic and advanced warn users that personal data might be "accidentally" sent to Microsoft, although they promise to neither identify nor contact you. Opting out of SpyNet, however, is not an option in Security Essentials.

Security Essentials benefits greatly from having a simple, streamlined interface. There are four tabs, each with a concise and understandable label: Home, Update, History, and Settings. The program also uses easy-to-grasp labels, imported from OneCare: green for all good, yellow for warning, and red for an at-risk situation.

From the Home window, you can run a Quick Scan, Full Scan, or Custom Scan, and a link at the bottom of the pane lets you change the scheduled scan. The Custom Scan lets users select specific folders or drives to scan, but it doesn't allow for customizing the type of scan used. For example, you're not going to be able to choose to scan only for rootkits or heuristics, as you can with other security programs. The program installs a context-menu option for on-the-fly scanning in Windows Explorer, too.

The Update pane manages the definition file updates, with a large action button, and History provides access to a spreadsheet-style list of All detection items, your Quarantine, and items you've Allowed to run. Although it's a basic layout, this no-frills approach to security could prove appealing to computer users who are overwhelmed by more detailed security choices.

Users can choose between two options for SpyNet, but no way to not contribute to it.

(Credit: Screenshot by Seth Rosenblatt/CNET)

The Settings window allows users to further customize the program by scheduling scans, toggling default actions to take against threats, adjusting real-time protection settings, creating whitelists of excluded files, file types, and processes, and the aforementioned SpyNet options. There's also an Advanced option which is still fairly basic: here you can set Security Essentials to scan archives, removable drives, create a system restore point, or allow all users to view the History tab.

Security Essentials comes pre-configured to run a scan weekly at two in the morning, when your Microsoft thinks your system is likely to be idle. New malware signatures are downloaded once per day by default, although you can manually instigate a definition file update through the update tab. Attachments and downloaded files will be automatically scanned by Security Essentials.

Help is only available in the form of the standard offline Help manual that comes with all Microsoft programs. There's nothing fancy here.

Performance

I found that it installed in less than one minute, and completed its first Quick Scan in less than 30 seconds. The Full Scan took more than an hour to reach the halfway point, and this was borne out by tests performed by CNET Labs' benchmarks. Microsoft Security Essentials actually sped up the boot time of our test computer by more than two seconds, and it sped up the shut-down time by more than two and a half seconds. However, compared to major security vendors it was significantly slower at scanning--Security Essentials took 2,340 seconds to scan, whereas most scans would clock in between 1,000 and 1,100 seconds.

The program comes with a few options for customization, but not many.

(Credit: Screenshot by Seth Rosenblatt/CNET)

In our iTunes decoding test it scored similarly to its competition, about 7 seconds slower than an unsecured computer. In our MS Office test and media multitasking tests it was faster than some--503 seconds versus 552 seconds for Norton AntiVirus 2010 in the Office test, and 844 seconds versus 876 seconds for Trend Micro Internet Security Pro in the media test.

While running the Full Scan, I noticed that it took up about 86 MB of RAM. However, it felt far lighter, and I was able to perform resource-intensive tasks like uploading photos without any noticeable freezes.

Third-party virus detection efficacy scores were not available at the time of writing, and it's not currently clear whether Security Essentials shares the same detection engine as Live OneCare. However, CNET reporter Ina Fried mentioned that Security Essentials stopped her from accidentally coming down with a case of Koobface.

Conclusion

Microsoft Security Essentials is a lightweight security app that people might turn to for a number of key reasons. It's easy on the system resources, it's easy to figure out how to use, and it comes pre-configured. It only works on legally licensed Microsoft computers, which is understandable but potentially leaves a large segment of the unprotected population still unprotected. You can't opt out of contributing to SpyNet, which isn't understandable at all. Overall, it's recommended for those who want something to set and ignore, but users who want more robust configuration choices or don't want to contribute to the cloud should look elsewhere.

September 2, 2009 9:00 AM PDT

Remove viruses from an infected PC, and keep them from coming back

by Dennis O'Reilly
  • 30 comments

Our family PC gets quite a workout. It's a five-year-old machine that runs Windows XP and is used primarily by my daughter and teenage grandson for instant messaging, e-mail, social networking, and downloading audio and video files. Since I rarely use the system, I didn't notice that its antivirus subscription had expired.

Which explains why I was a bit surprised when my grandson called when I was out of town to tell me that the PC was acting strangely. Ads appeared on the desktop as soon as Windows started and Firefox and other programs would occasionally close without warning or fail to open at all.

I immediately suspected a virus and instructed my grandson to perform a virus scan. Unfortunately, the machine's antivirus app had gone AWOL. I talked him through the process of using System Restore to revert the PC to an earlier time. This improved matters somewhat, but the system continued to act flaky.

When I returned from the trip, I started the troublesome machine and attempted to open the Microsoft Update site to make sure its copy of XP was up-to-date. But the malware had managed to disable several Windows services intermittently, including Services.msc, so Internet Explorer would shut down repeatedly.

At this point, I was seriously considering a hard-disk reformat and XP reinstall. I even had the XP installation CD in the drive and was ready to begin the process. But even though my daughter and grandson assured me that they had backup copies of all their personal files, I decided to try one more time to salvage the existing setup.

I'm very glad I did, because it turns out there were lots of vacation and holiday images and videos on the machine that hadn't been backed up. First, I installed a free copy of Malwarebytes' Anti-Malware antivirus program on the infected PC, updated the app's virus definitions, and ran a complete scan.

Malwarebytes Anti-Malware scan report

The initial Malwarebytes Anti-Malware scan detected 104 separate infected files and folders.

(Credit: Malwarebytes)

That first scan turned up a mere 104 infected files and folders. Here's a list of the nasties the machine had picked up:

• Trojan.Vundo
• Troja.Vundo.H
• Trojan.FakeAlert
• Rogue.Installer
• Trojan.Downloader
• Trojan. Dropper
• Trojan.Agent
• Worm.KoobFace
• Rogue.AdvancedVirusRemover
• Rogue.SystemSecurity
• Adware.BHO
• Rootkit.Agent
• Spyware.Agent
• Trojan.BHO
• Hijack.LSP
• Rogue.Multiple
• Disabled.Security

After viewing the report, I rebooted the PC and ran another malware scan. This time, Malwarebytes' app found only nine infected files.

The second Malwarebytes Anti-Malware scan report

The second Malwarebytes Anti-Malware scan detected only nine infected items.

(Credit: Malwarebytes)

I rebooted once more and ran yet another scan, which indicated that the PC came up clean.

The third Malwarebytes Anti-Malware scan report

The third Malwarebytes Anti-Malware scan indicated that all viruses and other malware had been removed from the infected PC.

(Credit: Malwarebytes)

Once I was assured that the PC was malware-free, I revisited the Microsoft Update site to download and install all the XP security patches the machine required. Then I sprang for the $25 version of Anti-Malware to get the program's real-time virus scanning and automatic updates.

I knew all attempts to alter the user behavior that led to the infections would be futile, so instead, I instructed my daughter and grandson to run Malwarebyte's scanner each time they start the system and just before each shutdown. That was a little over two weeks ago, and so far, the PC remains free of infection. Still, you can bet I'll be paying much closer attention to that machine from now on.

Originally posted at Workers' Edge
Dennis O'Reilly has covered PCs and other technologies in print and online since 1985. Along with more than a decade as editor for Ziff-Davis's Computer Select, Dennis edited PC World's award-winning Here's How section for more than seven years. He is a member of the CNET blog Network, and is not an employee of CNET.
June 26, 2009 1:16 PM PDT

Watch what Microsoft's new security app can do

by Seth Rosenblatt
  • 39 comments

The public beta for Microsoft Security Essentials, the free replacement for Live OneCare, is now closed, but that doesn't mean you've missed your chance to see what it's like.

In this First Look video, we look at the new interface, the new features, and the new limitations of the latest free antivirus to enter the market. Should AVG and Avira be scared? Watch and find out.

June 23, 2009 2:28 PM PDT

Microsoft Security Essentials not quite a must-have

by Seth Rosenblatt
  • 70 comments

Updated June 25 at 12:50 p.m. PDT: Several commenters pointed out a secondary scanning process that runs while a scan is running. While Microsoft Security Essentials uses little memory when not scanning, during a second round of tests it used 60MB to 70MB of RAM, while consuming around 200MB of Virtual Memory.

Updated June 24 at 11:30 a.m. PDT: The 75,000 available slots for testing Security Essentials have been taken. There is no word at the moment whether Microsoft will allow more testers to download the public beta in the future.

Microsoft on Tuesday released its latest foray into security software as a limited beta. Microsoft Security Essentials, known in development as Morro, is limited to 75,000 downloads in four countries: the United States, Israel, Brazil, and China.

Security Essentials contains all the basic features that users have come to expect from free security software: multiple built-in and customizable scan options, a scheduler, automatic definition file updates, a real-time defense shield, and rootkit protection.

It's been a bit hard to gauge user interest at this point. Despite the download limitations, I was able to download the installer onto one computer at 10:15 a.m. PDT, and another at 10:45 a.m. Microsoft has also said that the download cap might be lifted at a later date.

This hands-on will be limited to testing the on-board features since CNET doesn't maintain a virus zoo for security reasons. Also, users should note that Security Essentials will run a Windows Genuine Advantage check before installing. If you're running an illegal copy of XP or Vista, you're out of luck here. The program will run on Windows 7 RC, and there's a separate installer for users with 64-bit operating systems. The 32-bit installer for Windows Vista and Windows 7 was small, weighing in at 4.73MB.

The main interface of Microsoft Security Essentials is streamlined and uncluttered.

(Credit: Screenshot by Seth Rosenblatt/CNET)

If you're familiar with other free antivirus solutions such as AVG or Antivir, Security Essentials will probably strike you as an incredibly similar experience. The program opens with four tabs: Home, Update, History, and Settings. When you first start the program, it will ask you to update the definition files. This was a surprisingly fast process, taking about a minute when tested on two different Windows 7 computers.

After updating the definition files, it will ask you if you want to run a Quick Scan. On both of those Windows 7 machines, the Quick Scan worked true to its name and completed in less than 10 minutes. Quick Scans are good tools if you're worried about major infections, but deep scans are recommended regularly to maintain a higher level of protection.

The Home landing page summarizes your security status, indicating whether your system has been scanned successfully, whether real-time protection is on, and if your virus and spyware definitions are up to date. A pane on the right contains scanning controls, and a pane at the bottom tells you when your next scheduled scan is. There's a link to the scheduler, as well.

Security Essentials' Full Scan took nearly an hour and a half to finish, but only used 4MB of RAM while running.

(Credit: Screenshot by Seth Rosenblatt/CNET)

The Full Scan took about 86 minutes, which is a bit long for a deep scan on fairly new, regularly-scanned computers. I didn't think that the program would turn up any risks, but somewhat notably Security Essentials didn't turn up any false positives, either. The Custom Scan lets users select specific folders or drives to scan, but it doesn't allow for customizing the type of scan used. For example, you're not going to be able to choose to scan only for rootkits or heuristics, as you can with other security programs.

The program installs a context-menu option for on-the-fly scanning in Windows Explorer, too.

What did impress me was the shockingly small memory footprint. During the most resource-intensive action you can take with the program, the full system scan, it worked itself up to using only 4.6MB of RAM. More often than not, it hung around a few bytes lower, at 3.9MB.

The Update tab tells you your definition file version numbers, when your last update was, and has an Update button so you can force an update check. The History tab shows only files detected as potentially harmful. You can sort files it's detected according to All Detected Items, Quarantined Items, or Allowed Items.

User can customize some, but not all, aspects of the program.

(Credit: Screenshot by Seth Rosenblatt/CNET)

The last tab, Settings, is where most of the customization features reside. A left sidebar list contains options for Scheduling your scans, adjusting Default actions, tweaking Real-time protection, Excluding files, folders, file types, and processes from scans, Advanced controls, and managing your Microsoft SpyNet enrollment.

Yeah, Microsoft actually called something "SpyNet."

SpyNet, apparently, is a telemetry system Microsoft uses to quality-control definition-file updates after they've been sent out. According to the Microsoft news release, SpyNet reports back on the efficacy of old definition file removal and the implementation of new definitions, as well as how detection rates on false positives.

Security Essentials users must participate in SpyNet. The default option, Basic, reports to Microsoft on where a potentially infected file came from, what your action was, what the recommended action was, and whether the action taken was successful.

Security Essentials' SpyNet malware reporting feature.

(Credit: Screenshot by Seth Rosenblatt/CNET)

The Advanced membership in SpyNet will send even more information to Microsoft, including the location on disk of your potential infection, how it has affected your computer, and how it operates. For both Basic and Advanced SpyNet membership, Microsoft warns that, "personal information might unintentionally be sent to Microsoft," but that the company "will not use this information to identify or you or contact you."

On the surface of it, this sounds like a standard security software reporting process on malware behavior, although I don't know how deep other programs go into your system behavior. However, it's definitely odd that Microsoft has chosen to call it out in this way.

It's hard to gauge any antivirus program without reliable data on its detection and removal rates. Microsoft Live's OneCare security program has a reputation for low false positives and strong "new" detection rates, but it's not clear how much of Security Essentials is built on or from OneCare. At this point, I'd advise users who are curious about Microsoft Security Essentials to try it out, but I wouldn't recommend it yet as a primary security solution without more field testing.

March 18, 2009 3:38 PM PDT

Set it and forget it in Avira AntiVir 9

by Seth Rosenblatt
  • 15 comments

Avira AntiVir 9 introduces several new features including one-click threat removal, full antispyware and antiadware protection, a new heuristics detection engine, and enhanced program security.

Combined with its highly rated virus-killing abilities, AntiVir is one of the strongest free security programs around. Check out what you can expect in this First Look video.

March 17, 2009 2:26 PM PDT

Avira builds better free security in AntiVir 9

by Seth Rosenblatt
  • 59 comments

Avira AntiVir started making waves a few years ago, scoring high on well-respected third-party antivirus detection and removal tests. Released today exclusively on Download.com, AntiVir 9 doesn't appear to have changed much--but that's only because the interface sports the slightest of what's new.

Avira AntiVir 9 introduces one-click infection removal with multiple options for customization.

(Credit: Avira)

A refreshed banner logo tops the list of UI changes, but it's the long-awaited features in the free version of AntiVir that should pique most users' interest. Anti-spyware detection and removal is now available for the free version of AntiVir as well as the paid upgrades. There's new scanning tech that can crack open "locked" files and verify that they're not malicious, along with improved internal security to prevent AntiVir's files from being maliciously altered. AntiVir 9 also offers a rebuilt heuristic detection engine, and according to Tony Anscombe, director of consumer products for Avira, Download.com reader comments have been the impetus for the new one-click threat removal option--no more baby-sitting the scans.

The one-click threat removal is a nifty quarantining feature that logs and sets aside all detected threats so you can deal with them individually or as a group at the end of the scan. It's simple, but means that you can run a scan at night and not worry about the scan pausing and waiting for user input before it continues.

Click on the Configuration button on the right-side of the central pane, and check off Expert Mode on the upper left-side of the box that opens. In the options tree below it, go to Scanner, then Scan, then Action for Concerning Files. From there, you can choose an Automatic or Interactive reaction. Under Automatic, you can choose a primary and secondary action, as well as copying the file to the quarantine before taking any other action. Interactive offers you a round-up at the end of a scan, and Combined or Individual notification mode for users who want to deal with infections all at once or one at a time.

Except for the banner, AntiVir 9 looks exactly like AntiVir 8.

(Credit: Avira)

The other new features, from the anti-spyware to the rebuilt heuristic engine, are not as easy to demonstrate since we don't maintain a virus or spyware zoo at CNET for security reasons. However, it's worth mentioning that Avira has expanded the AntiVir free version to include their anti-spyware and anti-adware detections. In previous years, the premium version of AntiVir earned very high marks from both independent testers Andreas Marx (results) and Andreas Clemente.

As program upgrades go, AntiVir is worth some of the hoops that users must jump through to get on board. The upgrade is a time-intensive process, requiring some minor user input and rebooting your computer. Also, users will have to go to the Download.com product page and actively download the new installer. Version 9 won't be pushed to existing users for another month.

Savvy users will notice the removal of the on-demand e-mail scan, and AntiVir is still challenging--and by challenging, I mean a massive headache of pain--to fully uninstall. Despite these hang-ups and the nag screen that follows the multiple definition file updates that occur daily, AntiVir offers such effective protection and a well-rounded set of features that as long as the updates keep coming, it should remain on the top of any free antivirus users' list.

February 23, 2009 4:13 PM PST

New scareware sends you to fake Download.com reviews

by Seth Rosenblatt
  • 30 comments

Last week, BleepingComputer.com reported on how to remove a new variant of an old scareware. This new nasty, known most commonly as Antivirus2010 or Anti-Virus-1, points you to spoofed versions of Download.com, ZDNet, PCMag.com, and other software sites, demanding that you download their program to clean your computer. Of course, it does nothing of the sort, merely perpetuating the infection.

Antivirus2010, Anti-Virus-1, and other variants of the AntivirusXP infection have never been hosted on Download.com.

(Credit: Seth Rosenblatt/CNET Networks)

However, the manner and methods Anti-Virus-1 uses to get you there are extremely clever. The infection part of the malware does whatever it's been designed to do, so you can see that you've been infected with malware. What you don't realize at this point is that it's hacked your hosts file, too, so that when you go to a software site you don't ever make it to the site you're trying to get to.

You wind up on a skinned Web site that looks like the site you're expecting, but isn't. With the Download.com spoof, you can see that they're using our old design, which CNET abandoned last summer. Clicking on any link besides the download button will take you to the same page that the legitimate site would've taken you to. Hit the download button, though, and you get their fake malware remover, which in fact does the opposite, perpetuating the infection.

Removing the infection is tricky because of the differences between the variants. Some people have complained that they get locked out of their Task Manager, for example, but not all reports include that complaint. The fix that I cited for Antivirus XP 2008 may work, but users who have Windows XP Home Edition don't have a gpedit.msc. Home Edition users will have to edit their Registry directly.

Malwarebytes' Anti-Malware has proven to be one of the few malware killers that can effectively remove Antivirus XP 2008 and its variants, and it should work against the latest ones, too. The First Look video of Malwarebytes' Anti-Malware on the right will help you get started with the program.

Keep in mind that there is no substitute for cautious browsing. Don't install every Facebook app that comes your way, don't click on ads on unfamiliar sites or sites that are known vectors for attacks, and don't install software from anybody that's not a vouchsafed source.

I've pasted below the entire list from BleepingComputer of changes to your hosts file for your edification. Be warned that it may change as variants are developed.

O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com

O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com

O1 - Hosts: 217.20.175.74 a1.review.zdnet.com

O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com

O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com

O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com

O1 - Hosts: 217.20.175.74 www.reviews.download.com

O1 - Hosts: 217.20.175.74 reviews.download.com

O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk

O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk

O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com

O1 - Hosts: 217.20.175.74 reviews.pcmag.com

O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk

O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk

O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com

O1 - Hosts: 217.20.175.74 reviews.reevoo.com

O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk

O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk

O1 - Hosts: 217.20.175.74 www.reviews.techradar.com

O1 - Hosts: 217.20.175.74 reviews.techradar.com

(Via Ars Technica)

Search Download Blog posts

About The Download Blog

Download.com editors cover the world of downloadable software and beyond.

Add this feed to your online news reader

The Download Blog topics

Most Discussed