Website Information

End of Birthday Raffles! The raffles are now closed and been drawn. Check out the celebration forum to see if you've won!

The Securitycadets.com chat-room will soon return! Stick around for all details!

Search

Blogging Tools

Subscribe

  • Add to Windows Live
  • Add to Google Reader or Homepage
  • Add Security Cadets to Newsburst from CNET News.com
  • Subscribe in NewsGator Online
  • Subscribe to Yahoo
  • Add to My AOL
  • FeedBurner
  • Add to Technorati Favorites
  • Security Cadets - RSS-Get the Klip for this site
  • Spotplex

Copyright Notice

Creative Commons License
All articles are licensed under a Creative Commons License.
Every post is the opinion of the author. Contact Us for any issues.

A rogue on heat - VirusHeat

February 8th, 2008 by AndyAtHull

First time in a long time that we have directly posted about a rogue. In fact it was over a month ago.

Today we will be highlighting a rogue called VirusHeat. And as you can figure from the screenshot below. This one is a variant/clone/sister of VirusProtect, VirusProtectPro and many more. No surprises there.

VirusHeat

The details on who are behind it are no different either. Estdomains Inc and Ukrtelegroup Ltd are listed on the whois. And the URL to the infected site is:

www(dot)virusheat(dot)com

Avoid going to the site, unless you really know what you are doing.

Of course, once you have this flashing at you at 100 mph you want to know how you can remove it? Well, we have an automated removal guide in place HERE. But you can also get step by step guidance with a helper in our forum.

Have you been infected with this? Or have you got a question? Chat about this in details here for any questions.

Share this article/page with: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • e-mail
  • co.mments
  • blinkbits
  • blogmarks
  • del.icio.us
  • De.lirio.us
  • Facebook
  • Fark
  • Fleck
  • Furl
  • Google
  • LinkaGoGo
  • Live
  • Netvouz
  • NewsVine
  • Propeller
  • Reddit
  • Scoopeo
  • Sphinn
  • Spurl
  • Slashdot
  • SphereIt
  • StumbleUpon
  • TailRank
  • Technorati
  • TwitThis
  • YahooMyWeb

Filed under Rogue Programs, Security Related |

12 Responses

  1. bcowboy Says:

    Do I still need to download AVG even if I have mcAfee already downloaded on my computer?

  2. AndyAtHull Says:

    The reason we suggest AVG Anti-Spyware is because that detects and cleans any left overs. Plus potentional other malware

    I would guess by McAfee, you mean your anti-virus program. Well AVG AS is not an anti-virus program but anti-malware. Big difference.

    Our guide will disable AVG AS so it does not conflict with your primary av program. But in the interest of the infection the guide is about, yes, use AVG AS as part of the removal process. You can always uninstall it afterwards.

    Regards, Andy

  3. bcowboy Says:

    Thank you AndyAtHull for your help and responding to my message.

  4. bcowboy Says:

    can you please give me that addy again closed out the screen thinking you were responding to my message and it would of interfered with your responce. SORRY

  5. AndyAtHull Says:

    Do you mean to the removal guide for VirusHeat? Then here:

    http://forum.securitycadets.com/index.php?showtopic=5445

    That guide has all the relevent links

    Andy

  6. bcowboy Says:

    Hi Andy no I mean the web sight you gave me to get the smithfraud.exe at because I cannot find it when I put my comp. in safe mode. I have windows xp service pack 2 I dont know if thats the reason or not.

  7. AndyAtHull Says:

    Ok, well you can find a link on our downloads page:

    http://www.securitycadets.com/download/

    It will list the tool there. But if you still cannot find that click on the link below:

    http://downloads.securitycadets.com/SmitfraudFix.exe

    We mirror the tool.

    Andy

  8. bcowboy Says:

    Hello Andy I dont see the smitfraudfix.exe on my desk top when I start the comp. in safe mode. What should I do?

  9. AndyAtHull Says:

    Hello,

    Ok the next step would be, if you haven’t already, is to post this in the HJT forum.

    A blog commenting system won’t be a perfect communication solution for this problem.

    http://forum.securitycadets.com/index.php?showforum=2

    A helper should be with you asap.

    Andy

  10. bcowboy Says:

    Thank you Andy, I need to go out of town for a few days. Just thought I would let you know.

  11. bcowboy Says:

    Hello Andy I am back home again and want to Thank you for having patience with me.

  12. Barbara Says:

    These comments were helpful. I have been infected with the virus and am using your self help guide to try to get rid of it. It has led to a whole bunch more unwanted sites including
    illegal porn!

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.