Showing posts with label fake. Show all posts
Showing posts with label fake. Show all posts

Monday, August 23, 2010

Rogue Behaving Like A Retrovirus

Symantec writes in their blog about a rogue that pushes user to uninstall present antivirus protection. Rogue named as AnVi Antivirus shows a message about detected, uncertified antivirus software presence. Clicking on "ok" or "close" button (x on the top right corner of the window) triggers uninstall process of current antivirus protection by using that protection's own legit uninstaller.

At least solutions from Symantec, Microsoft, AVG, Spyware Doctor, and Zone Labs are detected by the pest. If any of these are present the pest will push user to uninstall.

Source

Tuesday, April 27, 2010

Malware Targeting iPad Users

Security company BitDefender warns about malware that is targeting iPad owners. E-mail invitation promises to keep iPad software updated “for best performance, newer features and security”. Purpose is to lure user to click included web link that is said to contain new version of iTunes software needed to update iPad. Instead of being iTunes update the file is actually malware that BitDefender detects as Backdoor.Bifrose.AADY.

Read the story here.

Sunday, February 14, 2010

Fake AV With Online Support

Fake antivirus programs showing false alerts of different malware types is unfortunately quite common sight nowadays. Live PC Care named rogue AV differs from other similar ones by having support function included. Yellow "online support" -button in the program launches live online support chat session with a live "support agent". The purpose of this is to alleviate doubt and to convince unaware user to purchase the product.

The whole story can be read from Symantec's Blog.

Tuesday, November 17, 2009

Fake Mailbox Deactivation Notices Spreading

Security company Sophos warns of malware that is being spammed in fake mailbox deactivation notices.

Contents of the email is following:

Subject: your mailbox has been deactivated

Body: We are contacting you in regards to an unusual activity that was identified in your mailbox. As a result, your mailbox has been deactivated. To restore your mailbox, you are required to extract and run the attached mailbox utility.

Best regards, [domain name] technical support.


To message attached utility.zip file contains trojan horse that Sophos detects as Mal/EncPk-LP.

Source

Tuesday, October 27, 2009

Fake Facebook Password Reset Confirmation Email Spreads Trojan

MX Lab warns in their blog about Bredolab trojan that is spread in fake Facebook Password Reset Confirmation email messages.

The body of message looks like this:

Hey <"receiver here"> ,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Facebook Team


Attached file contains variant of the trojan. Virustotal uploaded sample was detected bad by 14/41 scanners.

More details in MX Lab's blog.

Friday, May 15, 2009

Rogue Antivirus Program Takes System A Hostage

McAfee writes in their blog about fake antivirus program, branded as System Security 2009 and detected as FakeAlert-CO, that disables ability to run any application if user doesn't pay activation of the rogue. User is offered two subscription types: 2 year license for $49.95 or lifetime support license at a "discount". Rogue product website is made to look professional trying to make user more convinced.

Removal of the rogue is tricky since it doesn't offer remove -option and it doesn't appear in add/remove programs -window. Removal has to be done by rebooting system into safe mode and then remove it there.

Monday, March 9, 2009

New Rogue Software Around

There're two new rogue security programs around.

Malware Defender 2009 is a clone of System Guard 2009

Associated sites are:
209.249.222.48 Easywinscanner17 com
67.43.237.75 Malwaredefender2009 com
67.43.237.77 Gomaldef09 com

Source and example screenshots: Sunbelt Blog


Another new rogue software is Antispyware Pro 2009.

Its associated sites are:

205.252.24.226 Antispywarepro net
205.252.24.226 Scanspywareonline net
205.252.24.226 Netspywarescan com

Source and example screenshot: Sunbelt Blog

Saturday, January 17, 2009

Watch Out For Fake Obama Sites

F-Secure warns in its latest blog entry about fake sites trying to cash in with the inauguration of Barack Obama next week.

As an example F-Secure mentions www.superobamaonline.com. All links on that site point to a file named as speech.exe, which is a Waledec malware variant.

Other seen domains are for example:
www.greatobamaguide.com
www.superobamaonline.com
www.greatobamaonline.com
store.superobamadirect.com
store.greatobamaguide.com

Friday, January 9, 2009

Spammers Take Advantage of Google Code Project

"Google’s code-hosting project is the latest free service to be abused by web spammers", writes Chris Barton, McAfee researcher. According to Barton bad guys are creating plenty of new projects with this type of website that redirects user to fake codec download site.

The assault follows a bout of the same kind of abuse against Microsoft's comparable MSN Spaces beta site dating back a year. Barton states that the difference is that Google appears to automatically index code projects.

Barton's blog post can be read here.

Friday, October 3, 2008

Google Trend Exploited By Hackers

Criminals have once again found a new way to trick net users to load dangerous malware tells security company Webroot in its Threat Advisory. This time Google Trend service is used to reach the target. Google Trend is a service that lists the day's most frequently searched topics.

According to Webroot criminals check some top story of the day using Google Trends and then copy the topic to their fake blogs. Into these blogs they insert links that appear to be pointing to topic related videos. That way criminals can attract users to visit the site and it raises higher in the search engine results. When user tries to watch video behind the link the site tells that to see a video a codec must be installed. This codec is actually malware.

Anything new there? Well, yes and no. The codec trick itself is old one but exploiting Google Trends is a new thing which unfortunately raises amount of users who end up to these malicious sites.

Webroot gives 5 step recommendations to users to prevent this kind of malware attack. Those are:
1. Always have a current version of antispyware, antivirus and firewall product
2. Never download free product or purchase them from unknown Web sites and vendors, or peer to peer networks
3. Download videos and other multimedia files only from known and trusted Web sites or blogs
4. Make sure the computer is up-to-date by always installing the latest Microsoft or Apple security updates and
5. Use a credit card that has sufficient fraud protection when shopping and never use a debit card online.

Wednesday, May 21, 2008

KvmSecure Rogue Anti-Spyware Program Raises Its Head

KvmSecure is a rogue anti-spyware program - a fake spyware remover, which uses trojans, such as Zlob, to infiltrate the system. This parasite displays popups and fake system notifications to mislead the user so that he would think he's infected and therefore needs an anti-spyware program to dispose of the threats. KvmSecure's "licensed version" doesn't work and shouldn't be bought.

Bleeping Computer has a good removal tutorial here.