Showing posts with label Rogue Programs. Show all posts
Showing posts with label Rogue Programs. Show all posts

Wednesday, July 01, 2009

Somewhat new rogue Barracuda Antivirus gets wrath of legit Barracuda Networks

Another day, another rogue. This time it's named Barracuda Antivirus. I guess they wanted to ride the coattails of the real Barracuda firewall products. As usual, the fake Barracuda Antivirus will pop fake warnings and try to goad you into buying it.


The real Barracuda Networks had this to say:
This rogue ‘Barracuda Antivirus’ program is in no way affiliated with Barracuda Networks and is just one of a string of recent examples of hackers attempting to spread malicious programs using an established and trusted Internet security brand,” said Stephen Pao, vice president of product management for Barracuda Networks.

Barracuda is a successor to AntivirusBest. You can probably get rid of it with Malwarebytes Antispyware using the removal guide at Bleeping Computer for AntispywareBest. Screen shot of Barracuda Antispyware here.

More information about the real and legit Barracuda Networks here. They make hardware products to filter malware and spam for large networks, not really a home consumer solution.

Tuesday, June 30, 2009

AVProtection2009 Rogue

Saw an alert today about AVProtection2009. Like all rogue antispyware programs, it warns users about threats on their computer, which are usually false. It runs a somewhat real looking scan. After the scan, the program will offer to remove the threats if you purchase it.


Not too many details yet except what's at the Panda link above.

Thursday, December 11, 2008

Antivirus 360 Replaces Antivirus 2009 As New Rogue

The Vundo trojan is now using Antivirus 360 in it's effort to scam money out of victims. The name is play off of Norton 360 it appears. Like all rogue antispyware products, the malware that found it's way on your computer is from the same group that is trying to sell you the solution.

Antivirus 360 removal guide
found Bleeping Computer. Hijackthis log symptoms and files:

O4 - HKCU\..\Run: [13376694984709702142491016734454] C:\Program Files\A360\av360.exe

c:\Program Files\A360
c:\Program Files\A360\av360.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 360.lnk
%UserProfile%\Desktop\Antivirus 360.lnk
%UserProfile%\Start Menu\Antivirus 360
%UserProfile%\Start Menu\Antivirus 360\Antivirus 360.lnk
%UserProfile%\Start Menu\Antivirus 360\Help.lnk
%UserProfile%\Start Menu\Antivirus 360\Registration.lnk

Wednesday, June 11, 2008

AntiSpyCheck Rogue Program

AntiSpycheck is a new rogue spyware program. It's installed by the zlob trojan, giving fake alerts that try to get you to purchase it. The zlob trojan disguises itself as a video codec that is supposedly needed to view a video. It really installs spyware to make fake alerts and installs AntiSpyCheck to trick you into buying it.

Here are some lines from Hijackthis that you may find if you are infected:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
O2 - BHO: WarningBHO Class - {56FA7933-DC3E-403b-8D47-BB5E3F345A21} - C:\Program Files\AntiSpyCheck\IEWarning.dll
O2 - BHO: 514852 helper - {9420D9C5-E151-4D83-B9A6-27DE1A7A0E5F} - C:\WINDOWS\system32\514852\514852.dll
O2 - BHO: (no name) - {99BA268B-4021-4739-9945-3C774217FE75} - C:\Program Files\NetProject\sbmdl.dll
O4 - HKLM\..\Run: [AntiSpyCheck 2.1.0] "C:\Program Files\AntiSpyCheck\AntiSpyCheck.exe"
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
O22 - SharedTaskScheduler: campaniform - {5c7b71bb-6d49-4bdc-b60d-f9fe0481eb5f} - C:\WINDOWS\system32\kfcpnd.dll

Here are some files that you my have if you are infected with this trojan:

c:\Program Files\AntiSpyCheck
c:\Program Files\AntiSpyCheck\AntiSpyCheck.exe
c:\Program Files\AntiSpyCheck\IEWarning.dll
c:\Program Files\Mozilla Firefox\extensions\sotfone-tracker@sotfone.ru
c:\Program Files\NetProject
c:\Program Files\NetProject\sbmdl.dll
c:\Program Files\NetProject\sbmntr.exe
c:\Program Files\NetProject\sbsm.exe
c:\Program Files\NetProject\sbun.exe
c:\Program Files\NetProject\scit.exe
c:\Program Files\NetProject\scm.exe
c:\Program Files\NetProject\scu.exe
c:\WINDOWS\system32\kfcpnd.dll
c:\WINDOWS\system32\514852\514852.dll

For full details and a free removal guide, take a look at Bleeping Computer's AntiSpyCheck Removal Guide.

Friday, February 08, 2008

VirusHeat, Yet Another Rogue

The latest fake antispyware program is called VirusHeat. It does the usual fake warning ballon down by the clock telling you have spyware and other scary stuff. Luckily, it's not hard to remove, and the crew at Bleeping Computer have a VirusHeat removal guide.

SmitFraudFix can get this pest off your PC and it's free. So click the link above to see how to get this crap off your computer.


Here's what the fake warning looks like. It may say something different, but it's the same idea.

Tuesday, January 15, 2008

Macs Join the Rogue Program Club

F-Secure has reported about the first known rogue antispyware program for MacIntosh computers. Macsweeper is what it goes by. With the growing number of reported fake codec zlob trojans made for Macs, this doesn't surprise me. The first known Mac fake codec was reported just last November. Since then, there has been a steady release of Mac fake codecs to go along with the Windows versions. The last one discovered was on January 11th. If you go through Sunbelt's blog, you'll find many more.

For now, I'm not sure how you remove it, but it appears to be mainly a nuisance. More updates on this later.

Friday, December 28, 2007

New Rogue - MalwareCrush

They don’t stop trying do they? I’ve just had a report about another new rogue that goes by the name of MalwareCrush.

MalwareCrush is a rogue anti-spyware program that uses aggressive advertising and is installed onto your computer through the use of Trojans and other malware. This software is typically installed on your computer when you download programs masquerading as a video codecs required to view a video on a web page. In reality, though, when you install these Trojans, they will instead show fake security alerts in your Windows taskbar and install MalwareCrush onto your computer without your consent.

Once MalwareCrush is installed, it will automatically start and scan your computer. When the scan is finished it will have found the malware that actually installed it in the first place, but will require you to purchase the software before you can attempt to remove it. This is obviously a scam and you should not purchase the software under any circumstances.

Removal guide and screenshots at Bleeping Computer

Tuesday, November 13, 2007

Zangcodec and Virus Protect 3.8

A codec is a little piece of software that is needed so that you can play or stream some video files.  Personally I’ve never had to install a codec.. but then I don’t do a lot with that medium.

One of the biggest problems around on the internet at the moment is the Zlob trojan (and variants of it), people get stung because they are told they need a codec to run certain adult material.   Once installed the victim is plagued with pop ups from some fake antispyware program or other and the computer becomes more or less unusable.

Recently the stakes have been upped a little and the Apple Mac platform has been targeted along with Windows.  The latest malicious codec site is  Zangocodec as reported by Sunbelt.

The latest rogue program seems to be Virus Protect 3.8 which was put on the Smitfraud list by S!Ri yesterday.  S!Ri is the author of Smitfraudfix and has been keeping this essential tool updated for the last three years or so.  Thank you S!Ri.

If you want a bit more information about zangcodec then click here.   If you need to know how to use the Smitfraudfix tool then click here.  But I do suggest that you ask for assistance at one of the fantastic anti malware sites that will not only help to get you clean but will give you some good technical advice on how to avoid these sort of infections in the future.   You can find a list of anti malware sites here.

Monday, October 01, 2007

Media Motor Gets Slammed by FTC

The Federal Trade Commission slammed Media Motor with a $330,000 fine and a possible forfeiture of $3,595,925 in money that was "ill-gotten" according to the FTC. While the whole amount should be turned over, it is good to see that another malware maker has been slammed for ripping people off.

Back in November, the FTC charged ERG Ventures, LLC with tricking people into downloading Media Motor by hiding it in free downloads. Screen savers and video files were two of the most common types of files. Even today, many spyware programs use free videos to get their crap onto your computer. The Zlob trojan, responsible for the likes of SpyAxe, SpyFalcon and VirusRescue, used videos and a fake codec to get on your computer. Anyways, once Media Motor got on your computer, it would your home page, track you, try to disable your antispyware programs and generally be a pain to get rid of.

Here's an excerpt from the FTC report describing the penalties that Media Motor is subject to:

The order will permanently bar the defendants from distributing software that interferes with consumers’ computers, including software that tracks consumers’ Internet activity or collects other personal information; generates disruptive pop-up advertising; tampers with or disables other installed programs; or installs other advertising software onto consumers’ computers. The defendants will also be required to fully disclose the name and function of all software they install on consumers’ computers in the future, and to provide consumers with the option to cancel the installation after viewing the disclosure.


You can read the full report on the FTC media Motor press release here.

The Federal Trade Commission is the branch of the US Federal Government that handles fraudulent Internet web sites and programs. You can file a complaint against any web site or computer program by visiting the FTC complaint page and filing a complaint. You can also call 1 877 382 4357 to complain as well.

Monday, September 24, 2007

RogueRemover and a Short History of Rogues

RogueRemover has been around for awhile, but I like to be thorough and wait till I know a program is good. There's lots of talk here and around the Net about rogue antispyware programs, but what are they?

In short, it is a program that is supposed to be helpful but really is useless or even has been put on your computer to try to sell itself. The most famous of these are the ones from the Smitfraud group from the Russian mob scam artists. Names like SpyAxe, SpyFalcon and WinAntivirus are just a few of them. Back in 2005, the first one, SpyAxe, hit the Internet and ticked off alot of people. I posted removal instructions on my old blog on how to remove it. Most of the 200,000+ page views for that one post came in the first 3 months. By then, SpyAxe was out and a new rogue SpywareStrike was screwing up people's computers. Many people found out it was easier to use trojans to infect people's computers and then offer a solution. Now there are many of these rogue programs.

SmitFraudFix targets the actual trojan, usual called zlob, to rid your computer of these pests. RougeRemover targets the fake programs that get installed. So here i'll start giving updates for RougeRemover, since it is a good tool to remove the fake antispyware programs we call rogue programs.

RogueRemover is a utility that can remove various rogue antispyware, antivirus and hard drive cleaning utilities. Rogue applications are applications that rather than remove spyware, provide false positives, distribute malware or spyware, advertise, or provide useless uninstallers.

You can download RogueRemove from Malwarebytes.org and a few other sites like MajorGeeks. You can read more about it at Malwarebytes.

Here are the recent programs it removes, plus selected older rogues.

Current Version is 151

Added: AntiVirGear, CryptDrive, OSBodyGuard, PCSleep Error Cleaner, SafeStrip, SpywareLocker, SystemDefender

Updated: Rogue.Infector

Previous additions: virusProtectPro, VideoAccessCodec, Spyware-Sweeper, SpyHeal, VirusHeal, BPS Spyware Remover, SpyLocked, Ultimate Cleaner, MalwareWiped, SpyCrush, SpyDawn, VirusRescue and oldies like SpyAxe and SpyFalcon

Friday, September 14, 2007

AntiVirGear New Rogue to Remove

AntiVirGear is the newest fake antispyware program connected with the zlob trojan. It's been awhile since there has been a new one, but this program is garbage just like the rest. It will find spyware on your computer and then offer to remove it after you pay.

Bleeping Computer has a guide on how to remove AntiVirGear until most reputable antispyware programs are able to fix it.

Files and information related to AntiVirGear:

Hijackthis entry:

O4 - HKLM\..\Run: [AntiVirGear 3.7] "C:\Program Files\AntiVirGear 3.7\AntiVirGear 3.7.exe" /h

Files:

C:\Windows\System32\wqzdtjg.dll
C:\Windows\System32\ddllup.dll
C:\ProgramFiles\AntiVirGear 3.7

Thursday, June 28, 2007

VirusHeal

VirusHeal is the newest rogue program. Some say it's SpyHeal with a new name. Sunbelt reports it comes along with DVDacess, a fake codec that different web sites will trick you into installing. The whole thing is a scam. They trick you into installing the codec so you will get infected. Then they try to sell you the cure, this time called VirusHeal.

You should be able to remove this pest by using Smitfraudfix. Being new, you may have to manually uninstall Virusheal, but the zlob trojan that is making the pop ups and fake warnings should be removed.

Websites to avoid and to add to block lists:

Virusheal.com
inc-codec.com


Some of the files and registry entries that are added by VirusHeal:

%ProgramFiles%\VirusHeal 3.7\VirusHeal 3.7.exe
%ProgramFiles%\VirusHeal 3.7\msvcp71.dll
%ProgramFiles%\VirusHeal 3.7\msvcr71.dll
%ProgramFiles%\VirusHeal 3.7\antispy.vh
%UserProfile%\Start Menu\Programs\VirusHeal 3.7\VirusHeal 3.7.lnk
%UserProfile%\Start Menu\Programs\VirusHeal 3.7\VirusHeal 3.7 Website.lnk
%UserProfile%\Start Menu\Programs\VirusHeal 3.7\Uninstall VirusHeal 3.7.lnk



HKEY_CLASSES_ROOT\CLSID\{FA222968-C5BA-FA9F-6458-C63131328081}
HKEY_CLASSES_ROOT\Interface\{18F5E902-679B-4B12-BF13-BC16D02F7D80}
HKEY_CLASSES_ROOT\Interface\{1AEAAA6B-4EF6-488E-82F8-36E766F29220}
HKEY_CLASSES_ROOT\Interface\{39B58318-66E6-48D7-AB96-0208DA05FCEB}
HKEY_CLASSES_ROOT\Interface\{4E213C44-13CB-4E9F-8CBF-4C1A9EB9C2C9}
HKEY_CLASSES_ROOT\Interface\{518A840C-6647-4832-AB7D-CE4B314A1027}
HKEY_CLASSES_ROOT\Interface\{624F9366-D33B-492A-A3B7-217C14255A42}
HKEY_CLASSES_ROOT\Interface\{6AC53946-8646-42E6-B470-AD77648364C2}
HKEY_CLASSES_ROOT\Interface\{7867D50C-8459-4B0A-84B3-4F2D469A6C95}
HKEY_CLASSES_ROOT\Interface\{7BD05E7F-D2F0-42EA-B886-1A627968F9B0}
HKEY_CLASSES_ROOT\Interface\{899AE9A8-5BDD-4B68-A662-FCCDB4F9D91B}
HKEY_CLASSES_ROOT\Interface\{8B32593C-EBD5-4082-9059-708C19E153F3}
HKEY_CLASSES_ROOT\Interface\{A6FF06A4-5DC7-42D6-8960-141E676B1B8A}
HKEY_CLASSES_ROOT\Interface\{AF3E3CCE-C353-4D29-B30D-3F0E1A7C8E5B}
HKEY_CLASSES_ROOT\Interface\{C3FC451D-2851-4F5D-80D9-B15858E7B468}
HKEY_CLASSES_ROOT\Interface\{C4132813-FCCA-4F83-AF12-DC6D36F3FAB8}
HKEY_CLASSES_ROOT\Interface\{E3842CE8-9D0F-4809-A0D7-BF013946BB24}
HKEY_CLASSES_ROOT\TypeLib\{1963F207-DC66-4D6C-9A3C-B4DE1DEC24E4}

Tuesday, June 19, 2007

System Live Protect and SpyHazard

Two new rogue programs are out there on the Net trying to get you, System Live Protect and SpyHazard. Both should be avoided like the garbage they are.

System Live Protect is trying to pass itself off as a Microsoft program and playing off the name of the real Windows Live Onecare. I just finished testing Live Onecare and the screen shots of System Live Protect look too similar. They are definitely trying to trick people. Anyways, I don't have any copies of this joke to test, but you can look at Bleeping Computer's System Live Protect removal help. Hijackthis logs will show this if you have this rogue:

O4 - HKLM\..\Run: [LiveProtect] "C:\Program Files\LiveProtect\LiveProtect.exe" -h

SpyHazard is another rogue. This one looks pretty generic compared to it's fellow fake antispyware programs like SpyCrush and SpyLocked. You'll find the following line if you run Hijackthis:

O4 - HKLM\..\Run: [SpyHazard] C:\Program Files\SpyHazard\SpyHazard.exe /h


In add or remove programs you'll find SpyHazard 3.1 which you should uninstall. It will leave behind some other junk, so follow another Bleeping Computer removal guide to get rid of the rest.

Saturday, June 09, 2007

SpyCrush Updates Itself But Is Still a Rogue

SpyCrush came out back in February. It and SpyLocked were making the rounds as the latest fake antispyware programs that infected your computer and then tried to get you to buy them to remove the spyware that they put on your computer. SpyLocked seems to have gone away or turned into SpyLocked, which has been updated. No matter what, don't buy it or use it. It's a scam.

You'll see some or all of the following entries in Hijackthis:

O4 - HKLM\..\Run: [SpyCrush] C:\Program Files\SpyCrush\SpyCrush.exe /h

O4 - HKLM\..\Run: [SpyCrush 3.1] "C:\Program Files\SpyCrush 3.1\SpyCrush 3.1.exe" /h

O4 - HKLM\..\Run: [SpyCrush 3.2] "C:\Program Files\SpyCrush 3.2\SpyCrush 3.2.exe" /h


Take a look at Bleeping Computer's SpyCrush removal instructions on how to remove this threat

Saturday, May 05, 2007

Spyware Warrior Rogue/Suspect List Updated

Spyware Warrior have updated their Rogue/Suspect Anti-Spyware Products & Web Sites. Below are the new rogue antispyware products:

AntiVirusPCSuite
ExpertAntivirus
SpyVampire
SpyWare Secure

Total applications listed: 349

Spyware Warrior Rogue/Suspect Antispyware Products and Websites

Friday, April 20, 2007

Malware Stopper & Malware Panacea

A new Spysheriff, PestTrap, PestCapture variants have been found. They go by the name of Malware Stopper & Malware Panacea. These are just more fake antispyware programs that get installed by the zlob trojan. The web sites malware-stopper.com and malwarepanacea.com that should be avoided and will be added to the block lists soon I'm sure.

There's no new instructions on how to remove these two pests, so using the regular spyware removal instructions should be enough.

Monday, March 26, 2007

AOL Has Winfixer Trojan On It's Website

A few days ago, fellow MVP Sandi Hardmeier reported that Winfixer was being installed from some of the advertising on Aol.com web pages. You can see on her Gotcha! Winfixer and Aol post all of the details. In short, Aol has advertising banners that show many ads. One of them will load from errorsafe.com and then attempt to trick you into installing System Doctor. A few screen shots can be seen here. The whole thing is a scam to trick people into buying the program. AOL needs to remove these ads immediately. By allowing them to stay, AOL is allowing people's computers to get infected with spyware and letting the spyware creators make money.

Winfixer is one of many names the rogue program goes by. There are different versions that use different names. Some of them are: System Doctor, WinAntiVirus, ErrorSafe and DriveCleaner. They aren't fake antispyware programs, but they claim to find problems with Windows, kind of like registry cleaners. The problems reported by one of these programs aren't real. They are used to trick you into buying the program. You will also get pop ups and other unwanted reminders to buy the program. Sunbelt CounterSpy targets these programs under ErrorSafe. Antivirus programs detect Winfixer as well. Symantic and McAfee have detailed web pages that describe this threat as well.

AOL needs to take action to protect their users immediately. While the Winfixer ads are infrequent, the large number of people who visit aol.com means that many people are being put at risk. Also, by hosting the ads for Winfixer, this means Aol is directly responsible for letting these spyware creators make money. Any delay in removing the Winfixer trojan from Aol is not acceptable.

Monday, March 19, 2007

Spylocked Is Yet Another Rogue Program

A new rogue named SpyLocked is the latest fake antispyware program found today. SpyLocked will be installed on your program by one of the Zlob trojans from installing a fake codec to view video files. You don't really need to install the fake codec, but you will be tricked into installing it so SpyLocked can get onto your computer. Once it is on your computer, you will get pop ups and warnings that you have spyware. Then you will be coerced to buy SpyLock or one of the other fake programs.

The following is one of the fake warnings you will see when you get infected. This is from an earlier rogue program SpyFalcon, but the same kind of warning happens with SpyLocked.



Removal instructions can be found at Bleeping Computer's How to remove SpyLocked instructions. In a few days, the programs used in my earlier post, Easy Fix For Spyware and Virus Alert post should be updated to remove SpyLocked.

Monday, February 12, 2007

SpyDawn Rises As Newest Rogue Antispyware Program

SpyDawn has been reported by Bleeping computer as the newest fake antispyware program. Removal instructions have been posted as well as screen shots, including the pop up warning by the clock. The web page spydawn.com should be added to all the security black lists soon.

Here is the spydawn.com domain information. IP location is in the Ukraine with Inhoster Hosting company. The domain is registered through Estdomains. Both bad signs.

Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website: http://www.estdomains.com

Domain Name: SPYDAWN.COM

Registrant:
ODS ltd
Robyn Turner turnrobyn@gmail.com
Level 11 Toowong Tower
9 Sherwood Road
Toowong
null,Qld 4006
AU
Tel. +61.38761200

Creation Date: 12-Nov-2006
Expiration Date: 12-Nov-2007

Domain servers in listed order:
ns3.dragracers.biz
ns2.dragracers.biz
ns1.dragracers.biz


Administrative Contact:
ODS ltd
Robyn Turner turnrobyn@gmail.com
Level 11 Toowong Tower
9 Sherwood Road
Toowong
null,Qld 4006
AU
Tel. +61.38761200

Technical Contact:
ODS ltd
Robyn Turner
Level 11 Toowong Tower
9 Sherwood Road
Toowong
null,Qld 4006
AU
Tel. +61.38761200

Billing Contact:
ODS ltd
Robyn Turner
Level 11 Toowong Tower
9 Sherwood Road
Toowong
null,Qld 4006
AU
Tel. +61.38761200

Status:ACTIVE

SpyCrush Is Another Fake Antispyware Program

I've been busy with real life and haven't posted much over the last few months, but the bad guys have been busy. SpyCrush is the latest in the line of fake spyware removal programs that try to trick you into buying it. The same people who make the program are the ones who put the spyware on your computer. Other programs like this include SpywareQuake, SpyFalcon, SpywareStrike, SpySheriff and many others.

Besides the pop up warnings and other advertising trying to get you to buy it, you'll see this line in a Hijackthis log:

O4 - HKLM\..\Run: [SpyCrush] C:\Program Files\SpyCrush\SpyCrush.exe

Smitfraudfix has been updated to remove this pest, so you can use the removal instructions here. Alternative fix is posted at Bleeping Computer. Information about spycrush.com and how the program SpyCrush resembles and older rogue VirusBurst located at Security Cadets.