We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Yinstall virus - watch out!

I've just been infected with a piece of malware/virus called Yinstall.exe.

I understand that this thing can get through paid-up and fully protected AV systems. Info off the net at 03.10.06

"Yinstall is a brand new Purityscan infection not widely detected by any anti-malware programs at present. You will have to delete this file manually while in Safe Mode. This won't be the only file you'll need to kill so anti-malware scans in safe Mode as already suggested is a must."

We've been in chaos all day with this and it got through Norton AV, switched off a few things, etc.

"Update: As of today, AVG Anti-Spyware (formerly Ewido) now detects this pest. Ran in Safe Mode, AVG should be able to remove it without too much fuss." (04.10.06)

Google it for more info.

Beware. Hope this helps. Good luck.
The atmosphere is currently filled with hypocrisy so thick that it could be sliced, wrapped, and sold in supermarkets for a decent price and labeled, 'Wholegrain Left-Wing, Middle-Class, Politically-Correct Organic Hypocrisy'.

Comments

  • VirusTotal report on Yinstall.exe as of the time of this post. Most of top programs have updated their definitions now.

    Antivirus Version Update Result
    AntiVir 7.2.0.25 10.10.2006 DR/Dldr.Purityscan.U.1
    Authentium 4.93.8 10.10.2006 no virus found
    Avast 4.7.892.0 10.10.2006 no virus found
    AVG 386 10.10.2006 Adware Generic.RDR
    BitDefender 7.2 10.10.2006 Dropped:Trojan.Downloader.Purityscan.U
    CAT-QuickHeal 8.00 10.10.2006 AdWare.PurityScan.u (Not a Virus)
    ClamAV devel-20060426 10.10.2006 no virus found
    eTrust-InoculateIT 23.73.18 10.10.2006 Win32/SecDrop.0pt!Trojan
    eTrust-Vet 30.3.3125 10.10.2006 Win32/Secdrop.MO
    DrWeb 4.33 10.10.2006 Trojan.MulDrop.4192
    Ewido 4.0 10.10.2006 Adware.PurityScan
    Fortinet 2.82.0.0 10.10.2006 Adware/PurityScan
    F-Prot 3.16f 10.10.2006 no virus found
    F-Prot4 4.2.1.29 10.10.2006 no virus found
    Ikarus 0.2.65.0 10.10.2006 no virus found
    Kaspersky 4.0.2.24 10.10.2006 not-a-virus:AdWare.Win32.PurityScan.u
    McAfee 4870 10.10.2006 potentially unwanted program Adware-MediaTickets
    Microsoft 1.1603 10.10.2006 no virus found
    NOD32v2 1.1797 10.10.2006 Win32/Adware.PurityScan
    Norman 5.80.02 10.10.2006 W32/PurityScan.AEX
    Panda 9.0.0.4 10.10.2006 Adware/MediaTickets
    Sophos 4.10.0 10.05.2006 no virus found
    TheHacker 6.0.1.094 10.08.2006 no virus found
    UNA 1.83 10.10.2006 Adware.PurityScan.7E0F
    VBA32 3.11.1 10.10.2006 AdWare.Win32.PurityScan.u
    VirusBuster 4.3.7:9 10.10.2006 no virus found

    Aditional Information
    File size: 176640 bytes
    MD5: a54d088ec296c06e4c77ea5245846934
    SHA1: 3b5634a5afc9ff0a94331e08054e479e30c91b72
    packers: Aspack
  • VirusTotal report on Yinstall.exe as of the time of this post. Most of top programs have updated their definitions now.

    Antivirus Version Update Result
    AntiVir 7.2.0.25 10.10.2006 DR/Dldr.Purityscan.U.1
    Authentium 4.93.8 10.10.2006 no virus found
    Avast 4.7.892.0 10.10.2006 no virus found
    AVG 386 10.10.2006 Adware Generic.RDR
    BitDefender 7.2 10.10.2006 Dropped:Trojan.Downloader.Purityscan.U
    CAT-QuickHeal 8.00 10.10.2006 AdWare.PurityScan.u (Not a Virus)
    ClamAV devel-20060426 10.10.2006 no virus found
    eTrust-InoculateIT 23.73.18 10.10.2006 Win32/SecDrop.0pt!Trojan
    eTrust-Vet 30.3.3125 10.10.2006 Win32/Secdrop.MO
    DrWeb 4.33 10.10.2006 Trojan.MulDrop.4192
    Ewido 4.0 10.10.2006 Adware.PurityScan
    Fortinet 2.82.0.0 10.10.2006 Adware/PurityScan
    F-Prot 3.16f 10.10.2006 no virus found
    F-Prot4 4.2.1.29 10.10.2006 no virus found
    Ikarus 0.2.65.0 10.10.2006 no virus found
    Kaspersky 4.0.2.24 10.10.2006 not-a-virus:AdWare.Win32.PurityScan.u
    McAfee 4870 10.10.2006 potentially unwanted program Adware-MediaTickets
    Microsoft 1.1603 10.10.2006 no virus found
    NOD32v2 1.1797 10.10.2006 Win32/Adware.PurityScan
    Norman 5.80.02 10.10.2006 W32/PurityScan.AEX
    Panda 9.0.0.4 10.10.2006 Adware/MediaTickets
    Sophos 4.10.0 10.05.2006 no virus found
    TheHacker 6.0.1.094 10.08.2006 no virus found
    UNA 1.83 10.10.2006 Adware.PurityScan.7E0F
    VBA32 3.11.1 10.10.2006 AdWare.Win32.PurityScan.u
    VirusBuster 4.3.7:9 10.10.2006 no virus found

    Aditional Information
    File size: 176640 bytes
    MD5: a54d088ec296c06e4c77ea5245846934
    SHA1: 3b5634a5afc9ff0a94331e08054e479e30c91b72
    packers: Aspack
    Flippin' Norton hadn't it seems.
    The atmosphere is currently filled with hypocrisy so thick that it could be sliced, wrapped, and sold in supermarkets for a decent price and labeled, 'Wholegrain Left-Wing, Middle-Class, Politically-Correct Organic Hypocrisy'.
  • quidsinquentin
    quidsinquentin Posts: 42,693 Forumite
    We thought that we'd got rid of this pest, but it appears to be more serious than we originally thought.
    The atmosphere is currently filled with hypocrisy so thick that it could be sliced, wrapped, and sold in supermarkets for a decent price and labeled, 'Wholegrain Left-Wing, Middle-Class, Politically-Correct Organic Hypocrisy'.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.