<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2008://3.3483-</id>
  <updated>2009-11-18T17:50:04Z</updated>
  <title>Comments for How can an infection like Antivirus XP 2008 happen?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:35442</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c35442" />
    <title>Comment from rodi on 2009-06-25</title>
    <author>
      <name>rodi</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>MalwareBytes is a good choice, however, I've found that Spyware Doctor does a better job when removing malware. As for Antivirus XP 2008 there are many many manual removal guide on the net. For example:<br />
<a href="http://www.bleepingcomputer.com/virus-removal/remove-antivirus-xp-2008">Antivirus XP 2008 removal at bleepingcomputer.com</a><br />
<a href="http://www.2-spyware.com/remove-antivirus-xp.html">Antivirus XP 2008 removal at 2-spyware.com</a><br />
</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-06-25T14:09:21Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32665</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32665" />
    <title>Comment from rohit dhir on 2009-01-03</title>
    <author>
      <name>rohit dhir</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>What is a virus which attacks or infects specific anti-virus software’s’ is known as?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-01-03T08:05:34Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32664</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32664" />
    <title>Comment from much guest on 2008-10-29</title>
    <author>
      <name>much guest</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Dude... You DON'T need to reinstall your (old) browser because of the redirects! :)</p>

<p>Easy trick. Go to Google, lookup whatever it is you want. Click on the 'cached' link. Doesn't seem to be affected by the redirects. ;)</p>

<p>Leo, I came to your site to find out WHAT IS THE SOURCE of these infections?</p>

<p>Thanks Big Guy! :)</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-10-29T18:58:33Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32663</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32663" />
    <title>Comment from Tim on 2008-09-16</title>
    <author>
      <name>Tim</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Well let me tell you what this friggin virus did to me. First off I accidentally agreed to the contract. DOH! Not realizing what I had done immediately I went about my business around the house and I come back and there is a "scan" going on by this xp 2008 virus saying I have several hundred trojans, cookies, and viruses. It then prompts me to purchase their product... LOL... I didn't w00t But I did want to update my mcafee because I knew it was outdated... Well they wanted money too so I decided not to go that route either. So I let the virus sit there for about 24 hours, hooked up to the internet, not giving it a second thought. When I came back to the computer, I found something very strange. All restore points had been erased, My ability to defrag was gone, my ability to customize my desktop settings was gone, and there were about 9 corrupt files in my c:\ drive and registry files and system32 files. Then I noticed if I left the mouse alone for about 3 minutes the system reboot would occur claiming I had just recovered from a serious threat. And this would happen every 3 minutes, making the virus even worse.... So I said ok time to deal with this little booger... So I went to google, searched antivirus xp 2008 and came up with mr. leo's recommended site and I clicked on it... with no success, so I tried again and it wouldn't connect... So I tried another and all I would get is a no connection page, or a redirect to a spam site. So I tried 3 different browsers... aol, mozilla, and internet explorer... all the same results... so I disassembled my computer took it to a friend of mine and said fix it. We tried to defrag.. nothing, system restore points.. all gone, and I allow MAXIMUM space for restore points creating one every other day, and with every install and un-install. ALL GONE! So we tried something else, I grabbed my old xp boot discs and using nero I backed up all the files I needed from my computer and got ready for a re-format... That little booger (me thinks) would not let me... No matter what we tried, the system would not boot up to a new system... Finally I bring the computer home, after 8 days of this. I open up a browser thats been sitting on the shelf collecting dust for 3 years w/out update... MSN Explorer that came with xp... lmao It was unaffected by the browser re-directs and I was able to get to trend-micro housecall and quarantine most of the malicous software associated with this worm, and then I used malwarebytes to get the rest. And now I have AVG Security protecting my @$$ bye bye mcafee.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-16T07:22:37Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32662</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32662" />
    <title>Comment from Packrat1947 on 2008-09-12</title>
    <author>
      <name>Packrat1947</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>The free Malwarebytes removes it.  The download webpage mentions $24.00, but that is for the fulltime protection.   Also, ComboFix at wwww.bleeping computers removes it too.</p>

<p>I use these two progs. to cleanup customer's computers.  Before running Combofix there is a tutorial that should be read.</p>

<p>Packrat1947</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-12T13:07:59Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32661</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32661" />
    <title>Comment from Patty on 2008-09-08</title>
    <author>
      <name>Patty</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I read the articles and I had a simular problem but mine was antivirus 2009 and I didnt open it my virus protector didnt catch so I uninstalled it in control pannel as it was there and then it kept moving around and poping up in different files on my computer. Every time I deleted it it changed the name finally my spyeraser caught it and removed it.  I know how you feel.  Cant trust anything</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-09T02:09:57Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32660</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32660" />
    <title>Comment from M. Malekzadeh on 2008-09-07</title>
    <author>
      <name>M. Malekzadeh</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>How can an infection like Antivirus XP 2008 happen?</p>

<p>First of all, I must emphasize that Antivirus XP 2008 keeps coming back in various innovative forms and as a FAMILY OF VIRUSES, each member supporting the others. Isn't this a marvelous idea?</p>

<p>Leo's assertion in this article that the main reason you get such a virus is your failure to update regularly the virus definition file of your antivirus program used to be true but no longer at all (see "e" below.)</p>

<p>Newer versions of Antivirus XP 2008 do the following to your computer, among other things, and unfortunately all these keep us wondering about what people at Microsoft have been doing to increase our computer security. </p>

<p>Specifically the new Antivirus XP 2008 virus:</p>

<p>a) Would reboot my computer any time my real antivirus program tried to remove some members of its family pack (Joke.Blusod and Trojan.Blusod)</p>

<p>b) Had disabled the Windows "Safe Mode" so I could no longer use the "Safe Mode" to do any debugging!!</p>

<p>c) Had infected Windows core and critical files in a Windows subdirectory called "System32." (Aren't all these files supposed to be protected by Windows itself?!!! ) For example:<br />
 <br />
	c1) "Wscript.exe" was a big culprit. Microsoft Windows protects and prevents deletion of this critical program by regenerating it immediately. I think few users, however, know how to monitor, stop, debug, or control any malicious "Host Script" the virus directs this program to carry out. I tried to copy and rename my Notepad.exe to Wscript.exe in the hope of preventing the malicious scripts getting carried out but could not do that -- A Windows wrong sense of self protecting critical files. Remember the Safe Mode was also rendered unavailable to me by the virus.<br />
 <br />
	c2) Yet Windows did not properly protect another file called "SVCHOST.EXE" in this subdirectory and the virus had infected it!! I cannot overemphasize how important this file is in providing or not providing malicious services to your computer!!!<br />
 <br />
	c3) The same was true for Windows Installer 3.1 (Not protected properly and infected).<br />
 <br />
d)Had disabled Microsoft's "System File Check" (SFC) program so it could not check on the validity and version of Windows critical files any more. For example, the command "SFC /SANNOW" would not work at all!<br />
 <br />
e) Had disabled my Symantec/Norton Internet Anti Virus and its LiveUpdate programs; so I could not update the virus definition files anymore.<br />
 <br />
f) Had disabled all my Internet communication lines with Microsoft!</p>

<p>g) Had inserted and opened several communication ports on the "Exceptions" tab of the Windows "Firewall" and was taking over my computer remotely.  Isn't it peculiar that once these ports are opened, Windows does not provide you a way to delete them from the "Exceptions" list of your computer Firewall? </p>

<p>h) Had removed the icon of "Network Connection Notification" from my System Tray to hide away the fact that my computer was being remotely accessed. <br />
 <br />
i) Had turned off and deleted all my "Windows Restore Points" so I could not revert to an earlier Windows configuration before the virus had attacked.<br />
 <br />
j) Had Done all the damage through Internet Explorer 7, which is supposed to have excellent security features (Microsoft people think so!!)</p>

<p>The Symantec/Norton Antivirus representative acknowledged the difficulties with "Antivirus XP 2008" virus and said the only thing to do was for me to use their special program by paying them $99 so their specialist in India would connect to my computer live and peruse it to remove the virus. The sales pitch was accompanied by many scary things that how dangerous this virus was, how I might lose my entire data and programs permanently, and how I might still have the virus even after reformatting my hard disk and starting with a fresh install of Windows, if I did it myself.</p>

<p>The Microsoft Technical Support MVP (Most Valued Professional) gave me the link to a program called "The Spyware Doctor" to remove the virus. So I downloaded the Spyware Doctor and run it to test my computer. It reported yes, my computer was infected with Antivirus XP 2008 but I had to buy their registered version in order to remove it (Does this ring a bell? Yeah... the "Antivirus XP 2008" virus itself!!) - Did I mention when I run the Spy Doctor under my Norton Antivirus, it reported that Spyware Doctor was trying to install a Trojan Horse on my computer?)</p>

<p>I feel most disappointed with Microsoft because my computer has been constantly updated for security by "Automatic Updates" through them. If someone is able to create "Antivirus XP 2008" to completely take over my computer through simple means I have described above and despite years of Microsoft's Windows updates for security, Microsoft must take a closer look at its aptitude or intentions.</p>

<p>Another trend unfortunately fermenting is the proliferation of so many companies and websites claiming their Antivirus programs are the ultimate answer to our virus problems. They offer FREE TESTS and Web Site HOUSE CALLS only to scare us further into buying their products and if we did not, infecting our computers with their own brand of viruses. We badly need special standards for naming and categorizing viruses so a claim of one company can be verified by an antivirus program from another.</p>

<p>Warmest regards,<br />
M. Malekzadeh</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-07T21:54:16Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32659</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32659" />
    <title>Comment from Geek Choice on 2008-09-05</title>
    <author>
      <name>Geek Choice</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>First off I am a field technician for a "Geek" pc service company. I have been dealing with the Antivirus XP 2008 and it's many variants for the last several months. About 50% of our clients fall for it and purchase the fake product and most clients wait several weeks before calling for help. This leads to additional infections getting on the pc.  I can say for sure that it gets by Mcafee completely. Even if fully updated it doesn't even see the infection. It also gets by Norton and Trend Micro PC-Cillin. They see it but can't remove it. Each of these products include firewalls.  I use Malwarebytes to remove it . But if it has been running on the system for a day or longer it may have pulled down more malware. So I also run Spyware Terminator, Combofix, Smitfraudfix, Hijack This. Also I clean out all temporary files before and after the cleanup with Ccleaner. All are free programs. I leave Spyware Terminator installed as it provides excellent real time malware protection for the system and doesn't interfere with anti virus programs. I recommend AVG for Antivirus protection. Windows defender I find to be almost useless and Spybot has become slow, bloated and tends to miss alot of malware. The same is true of Adaware. I no longer waste my time with these apps. I would not depend on them to keep your system safe.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-05T20:20:39Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32658</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32658" />
    <title>Comment from Dan on 2008-09-02</title>
    <author>
      <name>Dan</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I got rid of Antivirus XP 2008 by System Restore.  An easy way to get of any virus, and a good reason to keep System Restore enabled.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-03T03:09:48Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32657</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32657" />
    <title>Comment from Therese G on 2008-09-02</title>
    <author>
      <name>Therese G</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>A couple of weeks back now I had the same thing happen to me also.  Fortunately I knew something was wrong and never downloaded the file.  At the time I had up to date definitions for Kaspersky AV.  I check Manually on the hour and every hour.  My other Bells & Whistles never alerted me to it either.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-02T21:59:12Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32656</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32656" />
    <title>Comment from Fred on 2008-09-02</title>
    <author>
      <name>Fred</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Use Firefox with the "no script" add in.  Prevents all scripts from running unless you give them permission to do so.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-02T19:18:14Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32655</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32655" />
    <title>Comment from Adam Dunlop on 2008-09-02</title>
    <author>
      <name>Adam Dunlop</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Thankyou for this interesting article Leo.  I have come across this particular infection several times over the last few months, and I could not see anobvious way that it got into the systems.  Antivirus programs were up to date in all cases.  There is an interesting article that was published recently (UK magazine) "http://www.pcpro.co.uk/features/218199/is-the-virus-threat-real.html?searchString=is+the+virus+threat+real"  Which explorers the current threats.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-02T16:27:19Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32654</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32654" />
    <title>Comment from Sue on 2008-09-02</title>
    <author>
      <name>Sue</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>5 of my company's computers became infected with AntiVirus 2008 on August 12th.  We use CA also and it passed through without being detected.  I went to the CA site and it only noted that it was a trojan but didn't offer any updates or fixes to remove it.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-02T16:24:21Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32653</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32653" />
    <title>Comment from Jason on 2008-09-02</title>
    <author>
      <name>Jason</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>In my experience, Spybot Search and Destroy does a good job of removing Antivirus 2008 and Antivirus 2009. I do think, however, that I had to boot in Safe Mode to completely remove the 2009 version.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-09-02T14:34:03Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32652</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32652" />
    <title>Comment from Aaron on 2008-08-31</title>
    <author>
      <name>Aaron</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Don't feel alone in this scenario. </p>

<p>I run the IT side of things for a restaurant company and we also run Defender, Windows Firewall as well as the corporate version of Trend Micro on every workstation. We have seen this virus slip through all those layers as well as our Exchange AV solution and still infect machines that are locked down with no program install rights to the users on the machines at the time of infection. Looking at our exchange logs I see nothing to indicate that was the source of infection.</p>

<p>We are still not 100% sure how it infected, but I would suspect from a scripted website that was hacked or malicious to begin with. Our definitions on Defender and AV are automatically updated, and daily with respect to our AV so I would beg to differ with Leo's assumption that it was a result of your AV being out of date if you say it was current. </p>

<p>Thankfully it was removed fairly easily and it appears no harm was done, but as Leo has said before, you can never be 100% sure unless you reformat. We will likely do just that with any machine hit that is used for sensitive data and/or networked to the corporate office. But for the few road warriors that never connect to the network, the priority isn't as high for a total wipe and load.</p>

<p>I hope that allays your misgivings a bit.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-08-31T20:57:10Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32651</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32651" />
    <title>Comment from Mary on 2008-08-30</title>
    <author>
      <name>Mary</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>And as a follow-up reminder, neither product detected the infection when I ran full scans in Safe Mode.  These scans were after the damage had been done; ie: my desktop wallpaper had been changed to the Antivirus XP 2008 "warning", the Desktop Tab had been deleted from the Display dialog box, etc.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-08-30T16:17:17Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32650</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32650" />
    <title>Comment from Mary on 2008-08-30</title>
    <author>
      <name>Mary</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>I'm the person who asked this question. Without trying to start a flame war over which antivirus, or antispyware, or firewall is the best, let me just say that my combination of Computer Associates Antivirus, Microsoft Windows Defender, and ZoneAlarm Firewall have served me well. I've used this combination ever since Defender was still being called Microsoft AntiSpyware and CA Antivirus was called eTrust EZ Antivirus back in 2005. In fact, if you check a previous Ask-Leo article (Article 12056 | posted December 1, 2007 | How do I pick the right tools to protect my system?), he validated my use of CA AV and Defender as the same products he uses. </p>

<p>Be that as it may, Leo's response (for which I thank him) raises another question: "...always make sure that all anti-malware software is updating its database regularly..."  In the case of CA AV, it updates at least once every 8 hours and I always get a pop-up when "latest updates have successfully installed". If I open the CA AV it always says, "Your Anti-Virus is up to date and fully functional. Your computer is protected from the latest virus threats." If I do a manual update I'll get the message "Your security software is up to date." </p>

<p>Windows Defender updates on average twice a day and I always have the latest updates when I visit that update site. So this still leaves the question of "Why didn't my CA AV and/or Windows Defender stop this attack?"  I would have expected either product to automatically quarantine the threat until I decided what action to take. The fact that neither product did so and allowed my machine to become infected is troubling.</p>

<p>If anyone has any thoughts please share. </p>

<p>Leo... any additional comments about the lack of quarantine?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-08-30T16:08:10Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32649</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32649" />
    <title>Comment from Steve Myers on 2008-08-29</title>
    <author>
      <name>Steve Myers</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>It is not enough to have a good up to date anti-virus but one must also have an anti spyware program. I prefer spybot search & destroy because of its ability to block known spyware/adware and it user friendliness.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-08-29T16:28:38Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3483-comment:32648</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3483" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html#c32648" />
    <title>Comment from novice on 2008-08-28</title>
    <author>
      <name>novice</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Avast Home edition (free) has a web scanner that checks content in real time as the webpage loads. It doesn't try to judge the website itself as good or bad but it tries to make sure that nothing bad gets executed as a result of viewing the website.</p>

<p>But any anti-virus can only be as good as its virus definition. I have put mine on automatic update. Avast updates several times a day.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/how_can_an_infection_like_antivirus_xp_2008_happen.html">How can an infection like Antivirus XP 2008 happen?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-08-28T19:39:53Z</published>
  </entry>

</feed>
