Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Forums > System Security

Vista - Virus Response (Lab) 2009

Reply
 
Old 12-09-2008   #1 (permalink)


Windows Vista x64 Ultimate
 
 

Virus Response (Lab) 2009

Has anybody heard of the fake anti-virus "Virus Response 2009", and it's clone "Virus Response Lab 2009". Better yet, has anyone had any luck FULLY removing it?

I have 2 client machine here (XP Pro and Vista Home Premium), and I've manage to sort of get rid of this sucker, but still there remains a Taskbar Notification icon that I can't get rid of, and it's still there even in Safe Mode!

The only "solutions" I've found require downloading and installing some other piece of suspect software.

I've searched Avast, Kaspersky, Symantec and AVG websites, all of which have no references to this. Which makes me believe it's still too new...

My System SpecsSystem Spec
Old 12-09-2008   #2 (permalink)


Vista Ultimate 64bit SP2/
 
 

Re: Virus Response (Lab) 2009

Nope sorry this is the first time I heard of it. Thanks for the heads up about it too.
My System SpecsSystem Spec
Old 12-09-2008   #3 (permalink)


Windows Vista x64 Ultimate
 
 

Re: Virus Response (Lab) 2009

Quote  Quote: Originally Posted by mansrm81 View Post
Nope sorry this is the first time I heard of it. Thanks for the heads up about it too.

And it's a particularly nasty one too. In my attempts to remvoe it, I found traces of it's activities, and I've already given my customer a headsup to have all their online backing logins changed...
My System SpecsSystem Spec
Old 12-09-2008   #4 (permalink)


Vista Home Premium 32-bit & Vista Ultimate 64-bit both Service Pack 2 W7 Pro RTM 7600 32 & 64
 
 

Re: Virus Response (Lab) 2009

Hi Peter,

Have a look at this video from YouTube:
You messed up try again
My System SpecsSystem Spec
Old 12-09-2008   #5 (permalink)


Windows Vista x64 Ultimate
 
 

Re: Virus Response (Lab) 2009

Quote  Quote: Originally Posted by Dwarf View Post
Hi Peter,

Have a look at this video from YouTube:
You messed up try again
Thanks Dwarf, but our Indian friend in that video neglected to mention that somehow even the Manual Removal Instructions, in concert with CCleaner, HijackThis and Process Explorer does not fully remove it.

A taskbar noticfication still remains that I am unable to track down. It's not a service, because disabling ALL services doesn't stop it. Disabling ALL startup items doesn't stop it. Even removing Policy Run registry entries that MSCONFIG doesn't see didn't stop it.

This "Virus Response Lab 2009" somehow evens starts in Safe Mode Command Only! No matter what I do...
My System SpecsSystem Spec
Old 12-09-2008   #6 (permalink)


Vista Home Premium 32-bit & Vista Ultimate 64-bit both Service Pack 2 W7 Pro RTM 7600 32 & 64
 
 

Re: Virus Response (Lab) 2009

Hi Peter,

Can you post an image of this notification, together with any text associated with it?
My System SpecsSystem Spec
Old 12-09-2008   #7 (permalink)


Windows Vista x64 Ultimate
 
 

Re: Virus Response (Lab) 2009

Quote  Quote: Originally Posted by Dwarf View Post
Hi Peter,

Can you post an image of this notification, together with any text associated with it?
Your timing could not have been any worse! The customer has instructed me to just go ahead and use the restore disks, which I started about 15 minutes ago!

What I can tell you is what the icon in the noticifcation area looks like, and what it does.

It looks like the "Windows Updates" shield, except it flashes bettwen a Blue and Yellow version of itself, and if you click on it's notification balloon, or left click or right click on the icon itself, it tries to open up a page to virusXXXresponseXXX2009DOTcom (I've deliberately obfusticated the address for safety reasons with XXX and DOT). I've never allowed the page to open, so I can't say what happens beyond that....

Some extra files that I deleted, and that for some reason are not mentioned in any of the "solutions" I've found are "qttask.exe", "qttasku.exe" and "qttaskm.exe", all in "C:\Windows". They appear to be part of Quicktime, but End Tasking either one does nothing, as each monitors the other and just starts them up again, so cannot possibly belong to Quicktime...

Oddly enough, before I started the Recovery Disk, I also forcibly removed Grisoft AVG by deleting the Program Files entries, and the notification went away, so it would appear to have targeted AVG.
My System SpecsSystem Spec
Old 12-09-2008   #8 (permalink)


Vista Home Premium 32bit [x86] - SP2
 
 

Re: Virus Response (Lab) 2009

Quote  Quote: Originally Posted by Dzomlija View Post
Has anybody heard of the fake anti-virus "Virus Response 2009", and it's clone "Virus Response Lab 2009". Better yet, has anyone had any luck FULLY removing it?

I have 2 client machine here (XP Pro and Vista Home Premium), and I've manage to sort of get rid of this sucker, but still there remains a Taskbar Notification icon that I can't get rid of, and it's still there even in Safe Mode!

The only "solutions" I've found require downloading and installing some other piece of suspect software.

I've searched Avast, Kaspersky, Symantec and AVG websites, all of which have no references to this. Which makes me believe it's still too new...
Quote  Quote: Originally Posted by mansrm81 View Post
Nope sorry this is the first time I heard of it. Thanks for the heads up about it too.
Quote  Quote: Originally Posted by Dwarf View Post
Hi Peter,

Can you post an image of this notification, together with any text associated with it?
Uncertain if this will give you any new pointers Chaps, but it's the latest blog on the Microsoft Malware Protection Centre site;

Microsoft® Malware Protection Center : FakeXPA... Journey of a Rogue

May help in some small way.
My System SpecsSystem Spec
Old 12-15-2008   #9 (permalink)


Vista Home Premium x64
 
 

Re: Virus Response (Lab) 2009

I'm guessing the fakers don't use exact Microsoft interfaces is because they don't want to do anything wrong, like copyright violations. Wreaking havoc is ok though.
My System SpecsSystem Spec
Old 01-08-2009   #10 (permalink)


x64
 
 

Re: Virus Response (Lab) 2009

So ive had this virus response lab problem for about 2 months now, and have just ignored it....tell now. One day i was Instant Messaging when a window popped up and it said it was some virus remover, three of them popped up and then it started deleting a bunch of files and i right away clicked out of it.

About a week later(today) i havent been able to click anything because when i click something it refreshs a billion times or clicks the program a billion times.....I am sick of this virus.

PLEASE HELP
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Virus Bulletin ran tests for its August 2009 Comparative Review System Security
Microsoft Security Response Centre; July 2009 Out-of-Band Release Vista News
"Antivirus 2009" virus System Security
Pro Evolution Soccer 2009 (PES 2009) Vista Games
Got a virus alert on a virus that is over a year old System Security


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46