A folder av2009 is created normally in the program files with an exe av2009.exe running in the backgroud. Kill the exe and delete the file.
Also different variants of the same adware are in the wild.
A common symptom is a BSOD screen saver popping up every two mintues or five. A yellow/blue wallpaper stating the Machine being infected.
Almost every variants of this adware/virus is removed by MWAV. Just the leftovers of the virus, a screensaver and wallpaper needs to be removed manually. Since these files have no malicious codes in it.
Normally these wallpapers and screensavers are in the following path.
%windir%\system32\[RANDOM NAME].scr
%windir%\system32\[RANDOM NAME].bmp
it has been observed the names start with an lphc or blphc or rhc followed by a random string of alphabets.
Eg. lphcv8e4eab.exe
blphcv8e2eab.bmp
blphcv8e3eab.scr
Running latest mwavscan /explorer will change the default wallapaper and screensaver to none.
Keep checking for the pinfect.zip getting created everytime the mwavscan runs. If you doubt any suspicious behaviour sent this file to
samples@mwti.net