Beware of these rouge apps.
Showing posts with label Rogue Apps. Show all posts
Showing posts with label Rogue Apps. Show all posts
Thursday, October 15, 2009
Sysguard / Winifighter Clones
Here are some screenshots of the members of this scareware family:
![[gickr.com]_6c803672-8a5f-25e4-5109-31b55ebdf362 [gickr.com]_6c803672-8a5f-25e4-5109-31b55ebdf362](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vhKO7roEl173wm7pF7vJJY0Wbxvd-I2nsQEQYg74fg1kwd536wp0Zy2RtUh4tW9tbrM_tDJ7BXktfRSnkOWbSpxxUK5pJxbZqZ1-Ag0kiO5bVy-k7pOQjiLxmMi1q5HhElgbfSyat3-DaGCyesoJa7FmYgziK8uqoafwVtSbWgHsM=s0-d)
Beware of these rouge apps.
Beware of these rouge apps.
Labels:
rogue app,
Rogue Apps,
rogue av,
security,
Sysguard,
TrustCop,
TrustNinja,
Winifighter,
WiniShield
Tuesday, October 13, 2009
Winifighter Clone: TrustFighter
Another scareware has been spotted in the wild and it calls itself TrustFighter. This is a recent addition to the Winifighter family of scareware.
Same as other members of this family of scareware, as in a previous post, TrustFighter creates heaps of junk binary files in the %systemroot% and %system% directories.
Sample junk files are the following:
%systemroot%\51c0vzr24975.dll
%systemroot%\51cbthreatz1991.ocx
%systemroot%\524699py69fz.bin
%systemroot%\525z1vi9us4e4.cpl
%systemroot%\5294viz115.exe
%systemroot%\5eddaddwar9167z.dll
%systemroot%\5ezast95l495.dll
%systemroot%\5ezdaddware2359.cpl
%systemroot%\5z09s9yware545.cpl
%systemroot%\5z56th5eat19149.bin
%systemroot%\5z85thief22759.cpl
%systemroot%\5z99addware2835.ocx
%systemroot%\5z9bba5kdoor525.dll
%systemroot%\5z9cth5ef13559.cpl
%systemroot%\5zfdaddware950.bin
%systemroot%\5zfesparse709.exe
%systemroot%\6169th5zf99.ocx
%systemroot%\6210spywa5e192z.ocx
%system%\1905szea51146.cpl
%system%\190979iru57z7.ocx
%system%\190cszywa591879.exe
%system%\19105vizus1c.bin
%system%\19179virusz65.ocx
%system%\1930thief97z5.cpl
%system%\19559spamboz6bb.ocx
%system%\1958stezl2595.cpl
%system%\195b5hreat39894z.exe
%system%\19645worm7zd.exe
%system%\1969spz715.bin
%system%\1977zhacktool54d.cpl
%system%\19792troz5aa.bin
%system%\1987th5z92904.cplHere are some domains participating in this campain:
securityannounce(dot)com
securityadjust(dot)com
bestmalwaredetect(dot)com
pcprotectzone(dot)com
trustfighter(dot)comUnsuspecting users get set back by $49.95 from their hard-earned money.
Thursday, August 13, 2009
Social engineering trick leads to Rogue AV: MacroVirus
I was reading a blog about a Rogue AV then I noticed a suspicious comment on it:

It the user was recommending an antispyware program and gave us the following url:
Following the link, tinyurl does its magic and we are directed to:

If we believe everything we see and hear, we'll be downloading and installing a scareware:

Here we can see that the bad guys are clearly taking advantage of the url shortening service from tinyurl.com.
Also, you might notice, there's a striking resemblance between the following:
and
This is probably giving us a hint as to how the bad guys get paid.
If you got this scareware, remove it immediately.
It the user was recommending an antispyware program and gave us the following url:
www(dot)tinyurl(dot)com/qlft9cFollowing the link, tinyurl does its magic and we are directed to:
hxxp://macrovirus(dot)com/?hop=starbasiIf we believe everything we see and hear, we'll be downloading and installing a scareware:
Here we can see that the bad guys are clearly taking advantage of the url shortening service from tinyurl.com.
Also, you might notice, there's a striking resemblance between the following:
bassey edetand
hxxp://macrovirus(dot)com/?hop=starbasiThis is probably giving us a hint as to how the bad guys get paid.
If you got this scareware, remove it immediately.
Labels:
fake alert,
fake av,
macrovirus,
qlft9c,
rogue app,
Rogue Apps,
rogue av,
scareware,
security,
starbasi,
tinyurl
Tuesday, August 11, 2009
Rogue AV: Winifighter
We've talked about digital clutter on a previous post.
But this one's a real bugger. Winifighter creates heaps of junk binary files in the %systemroot% and %system% directories. The filenames, the contents, and filesize are all random. The names, however, contains bits and pieces taken from malware names such as the following:
backdoor
not a virus
spy
trojan
virus
wormThis one also, spoofs the Windows Security Center to give itself that authentic feel and advises unsuspecting users to register Winifighter.
Ad of course we also have those ever so genuinely adorable warning messages:
As always, I advise everyone to steer clear of these Rogue AVs.
Labels:
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware,
Winifighter
Thursday, August 6, 2009
Rogue AV: Antivirus Plus
Here's another Rogue AV out there, and it's being served by more than one domain:

Here's a list of some of the domains used to host this Rogue AV:

Stay away from these rogue domains and block them if you have any means of doing so.
Here's a list of some of the domains used to host this Rogue AV:
addedantiviruslive(dot)com
addedantivirusonline(dot)com
addedantivirusstore(dot)com
easyaddedantivirus(dot)com
freeantivirusplus09(dot)com
goodantivirusplus(dot)com
i-antivirusplus(dot)com
internetantivirusplus(dot)com
mybestantivirusplus(dot)com
myplusantiviruspro(dot)com
nextantivirusplus(dot)com
realantivirusplus09(dot)com
realbestantivirusplus(dot)com
yesantivirusplus(dot)comStay away from these rogue domains and block them if you have any means of doing so.
Labels:
Antivirus Plus,
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware
Wednesday, August 5, 2009
Rogue App: System Cleaner
I visited this rogue domain:
hxxp://antivirussecurescannerv3.com

The website proceeded to show me that it is scanning my machine for system errors and that it is doing a very wonderful job because it found heaps of problems on my machine and it is very eager to fix it.
To give the website some kind of authentic feel, it also showed me which browser I am using, my operating system, and my IP address.
It was also offering 60% discount on the product. Isn't that a good deal?
Now, if the dubious scanning and the overall feel of the website did not give away its real intentions, and if we are to be lulled into buying their software, well... hold on a minute!
If you notice that on my screenshot, the rogue website was giving some errors about the Windows TEMP folder, Internet Explorer temp files. But how can that be? As I mentioned on a previous post, I am not running Windows!
As usual, unsuspecting users get ripped off for a crappy software. So be careful!
hxxp://antivirussecurescannerv3.com
The website proceeded to show me that it is scanning my machine for system errors and that it is doing a very wonderful job because it found heaps of problems on my machine and it is very eager to fix it.
To give the website some kind of authentic feel, it also showed me which browser I am using, my operating system, and my IP address.
It was also offering 60% discount on the product. Isn't that a good deal?
Now, if the dubious scanning and the overall feel of the website did not give away its real intentions, and if we are to be lulled into buying their software, well... hold on a minute!
If you notice that on my screenshot, the rogue website was giving some errors about the Windows TEMP folder, Internet Explorer temp files. But how can that be? As I mentioned on a previous post, I am not running Windows!
As usual, unsuspecting users get ripped off for a crappy software. So be careful!
Thursday, July 30, 2009
Rogue AV: Antivirus Plus
Here's another Rogue AV using the same animated system scan on the internet browser as the one in a previous post

In some instances, Antivirus Plus uses this animated scan instead:

It also uses one of those warnings that look oh so genuinely sincere:

Then of course downloading and installing the rogue app give us the usual scan results:

Here's a list of domains currently serving this rogue app:

Because of the same animated system scan that they use, I reckon System Security and Antivirus Plus are two related rogue apps.
In some instances, Antivirus Plus uses this animated scan instead:
It also uses one of those warnings that look oh so genuinely sincere:
Then of course downloading and installing the rogue app give us the usual scan results:
Here's a list of domains currently serving this rogue app:
hxxp://adoimi.cn
hxxp://yourguardpro.cn
hxxp://yourcheckpoisonpro.cn
hxxp://yourfriskviruspro.cn
hxxp://antivirusplus09.com
hxxp://antivirusplus-ok.com
hxxp://addedantiviruspro.comBecause of the same animated system scan that they use, I reckon System Security and Antivirus Plus are two related rogue apps.
Labels:
Antivirus Plus,
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
System Security
Saturday, July 25, 2009
Heaps of threats found on my C: and D: drives! Oh wait, I'm not runningWindows
I have recently been working on Rogue AVs and there's one that made me chuckle.
Rogue website: zocleaner(dot)com

Visiting the rogue website warned me that my computer is infected and then it started scanning my computer as shown above. The image above was being displayed on my browser and was telling me that it had found heaps of threats already!
Clearly the rogue site was trying to fool me into thinking that my computer is infected. Duh! I wasn't even running Windows!
Downloading and installing the rogue application on a test machine gave me the usual outrageous scan results:

I advise everyone to be vigilant. People behind these rogue apps are out there to rip us off.
Rogue website: zocleaner(dot)com
Visiting the rogue website warned me that my computer is infected and then it started scanning my computer as shown above. The image above was being displayed on my browser and was telling me that it had found heaps of threats already!
Clearly the rogue site was trying to fool me into thinking that my computer is infected. Duh! I wasn't even running Windows!
Downloading and installing the rogue application on a test machine gave me the usual outrageous scan results:
I advise everyone to be vigilant. People behind these rogue apps are out there to rip us off.
Labels:
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware
Subscribe to:
Posts (Atom)