Showing posts with label Rogue. Show all posts
Showing posts with label Rogue. Show all posts

Thursday, January 20, 2011

New Twitter Worm Redirects To Rogue AV

Nicolas Brulez, Kaspersky Lab malware researcher, warns about new Twitter worm that's currently abusing Google's goo.gl redirection service to push surfers via chain of redirections to rogue AV site. Technical details and other related information can be read from correspondent Securelist blog entry.

Monday, August 23, 2010

Rogue Behaving Like A Retrovirus

Symantec writes in their blog about a rogue that pushes user to uninstall present antivirus protection. Rogue named as AnVi Antivirus shows a message about detected, uncertified antivirus software presence. Clicking on "ok" or "close" button (x on the top right corner of the window) triggers uninstall process of current antivirus protection by using that protection's own legit uninstaller.

At least solutions from Symantec, Microsoft, AVG, Spyware Doctor, and Zone Labs are detected by the pest. If any of these are present the pest will push user to uninstall.

Source

Saturday, May 29, 2010

U.S. Indicts Cybercriminals in Scareware Scam Case

The United States have accused three men of running an operation that used fraudulent ads to dupe internet users in more than 60 countries into buying more than $100 million worth of rogue anti-virus software. This was done by showing false virus warnings or other fake warnings about critical system issues on the screen and convincing users to buy treatments for those.

The defendants took advantage of online ads that they were able to post on different internet publishers websites. The publishers were not aware of true nature of the ads that rode on well known company names. Some scam products sold were DriveCleaner, ErrorSafe, Malware Alarm, Antivirus 2008 and VirusRemover 2008.

The press release can be read here.

Sunday, February 14, 2010

Fake AV With Online Support

Fake antivirus programs showing false alerts of different malware types is unfortunately quite common sight nowadays. Live PC Care named rogue AV differs from other similar ones by having support function included. Yellow "online support" -button in the program launches live online support chat session with a live "support agent". The purpose of this is to alleviate doubt and to convince unaware user to purchase the product.

The whole story can be read from Symantec's Blog.

Friday, January 8, 2010

Data Doctor 2010 - Combination Of Ransomware And Rogue

F-Secure introduces in their blog a pest that combines some elements of ransomware and rogueware. Trojan detected as DatCrypt encrypts Microsoft Office documents, video, music and image files and then shows user error message telling that files are corrupted. It advises user to download "recommended file repair software". This software detected, as Rogue:W32/DatDoc, lets user decrypt only one file unless a full version with price tag of $89.95, is bought.

Sunbelt has provided a decrypting tool to cure Data Doctor 2010 encrypted files.

Saturday, December 12, 2009

Fake Microsoft Support endorsement Used For Selling Rogues

Security company Sunbelt Software describes in their blog post how new DefenceLab rogue security program is taking advantage of social engineering by tricking infected users to believe Microsoft recommends it.

What it does is that it redirects infected systems to Microsoft Support portal. Instead of showing the real content it injects HTML code into the page making it look like Microsoft is recommending the purchase of the full version of the rogue. Users visiting the link on the Windows Support site referenced in the DefenceLab from a clean system will get a 404 'page not found' message.

Wednesday, September 30, 2009

Microsoft Security Essentials SEO Poisoning

Microsoft released yesterday its new Security Essentials real-time protection software for home users. Bad guys haven't let their chance to slip away.

Websense's alert warns about rogue links that malware authors have been able to get between legit results by using Search Engine Optimization (SEO) techniques. Results for Soft_71.exe file, one of those malicious files spread, were pretty low when the file was scanned on VirusTotal some hours ago.

Thursday, June 4, 2009

Rogue Software Campaigned In Twitter

PandaLabs write in their blog about rogue software campaigns that cyber-criminals are having in Twitter. In the attack, criminals are using zombie Twitter accounts to post messages with url links included. Clicking these links starts a series of redirections that finally ends up to malware serving websites.

Yesterday, all links were posted in messages under "PhishTube Broadcast" topic. However, new PandaLabs' blog entry states that over the past 24 hours the Twitter trends based attack has expanded to several thousand tweets targeting trendy topics on Twitter and the figures keep rising.

Friday, May 15, 2009

Rogue Antivirus Program Takes System A Hostage

McAfee writes in their blog about fake antivirus program, branded as System Security 2009 and detected as FakeAlert-CO, that disables ability to run any application if user doesn't pay activation of the rogue. User is offered two subscription types: 2 year license for $49.95 or lifetime support license at a "discount". Rogue product website is made to look professional trying to make user more convinced.

Removal of the rogue is tricky since it doesn't offer remove -option and it doesn't appear in add/remove programs -window. Removal has to be done by rebooting system into safe mode and then remove it there.

Monday, April 20, 2009

AV Antispyware - New Rogue Security Program

WinSpywareProtect, rogue security program family, has gotten a new member named as AV Antispyware.

Its associated sites are:
64.191.12.38 Av-antispyware com
195.88.81.74 Files scanner-antispy-av-files com
195.88.81.116 dl scan-antispy-4pc com
195.88.80.207 Int reporting32 com

Bleeping Computer has a tutorial that guides in uninstalling and removing this pest.

Monday, March 9, 2009

New Rogue Software Around

There're two new rogue security programs around.

Malware Defender 2009 is a clone of System Guard 2009

Associated sites are:
209.249.222.48 Easywinscanner17 com
67.43.237.75 Malwaredefender2009 com
67.43.237.77 Gomaldef09 com

Source and example screenshots: Sunbelt Blog


Another new rogue software is Antispyware Pro 2009.

Its associated sites are:

205.252.24.226 Antispywarepro net
205.252.24.226 Scanspywareonline net
205.252.24.226 Netspywarescan com

Source and example screenshot: Sunbelt Blog

Monday, January 26, 2009

New Rogue: Total Defender

"A new Rogue Antivirus program called Total Defender appeared over the weekend", writes Sean-Paul Correll in PandaLabs blog. Found parasite keeps its home behind Total-Defender. com domain located in Latvia.

"An interesting thing we noticed is that the Rogue did not attempt to scare us into purchasing it, rather telling us that the computer was secure after the scan. The Rogue authors are probably doing this to keep a high amount of Rogue installations active for the purposes of data theft or for hire services", Correll states.

Wednesday, January 21, 2009

Rogue Security Program Leaves Russian Systems Alone?

Alex Eckelberry posted to Sunbelt's Blog a snippet of Antivirus 2009 rogue security program. By looking at it seems like the parasite is instructed to not install itself on systems with Russian Windows.

Thursday, December 11, 2008

FTC After Scareware Scammers

"The US Federal Trade Commission (FTC) has announced a successful move to persuade a US district court to shut down a major player in the rogue anti-spyware business", writes Virus Bulletin.

"The defendants in the case are Innovative Marketing, registered in Belize but apparently based in Kiev, Ukraine, and ByteHosting Internet Services, run out of Cincinnati, Ohio, as well as several individuals running or profiting from the companies, both of which operated under a range of other names. The U.S. District Court for the District of Maryland approved the FTC's request to call a halt to the companies' activities and freeze the assets of those behind the scams."

FTC's press release can be read here.

Wednesday, May 21, 2008

KvmSecure Rogue Anti-Spyware Program Raises Its Head

KvmSecure is a rogue anti-spyware program - a fake spyware remover, which uses trojans, such as Zlob, to infiltrate the system. This parasite displays popups and fake system notifications to mislead the user so that he would think he's infected and therefore needs an anti-spyware program to dispose of the threats. KvmSecure's "licensed version" doesn't work and shouldn't be bought.

Bleeping Computer has a good removal tutorial here.