New Rogue: Antivirus Plus

by LS Anders on December 11th, 2008 in Rogues, Security Alert.

Recently we came across this rogue, Antivirus Plus. What makes this one different from others was that it was distributed directly as a fake video codec. They have now removed the fake alert step in between.

fake codec install


New Rogue - AntivirusTrigger

by Albin on December 5th, 2008 in Rogues.

AntivirusTrigger is a new rogue anti-spyware application and a clone of VirusTrigger. It will give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove the reported threats.

AntiVirusTrigger's GUI


ExtraAntivir and WinWebSecurity are two new rogue anti-spyware applications (FraudTools). They will give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove threats which doesn't exists. They are included in our latest definition update (0143.0001).

ExtraAntivir GUI 


More fake Codecs

by LS Anders on September 4th, 2008 in Rogues, Security Alert.

In our daily work we see many different attempts to trick a user to install dubious software.  One of the more common variants is to use fake video codecs, in other words claim that the user needs to download and install their software in order to see some videos. This could look something like this.
As soon as the user enters the page they will be presented with the following warning:

 

bar


XLG Privacy Control Center

by LS Anders on September 4th, 2008 in Rogues.

Recently we came across this clone of XLG Security Center.  XLG Privacy Control Center is being distributed as a fake video codec and through email spam.

gui


Hijacking rogue

by LS Anders on July 8th, 2008 in Rogues, Security Alert.

Recently we stumbled upon a rogue application that used a very aggressive way to get users to register and pay for a license. It all started with one downloaded file disguised as a movie file, using .wmv.exe extension and using a windows media icon. Once the file was run it started by warning you that your PC may be infected.


Zlob Copycat from IE-Antivirus?

by Albin on June 23rd, 2008 in Rogues.

During the past months it has been possible to download an executable file called c-setup.exe. It promotes itself in a similar way as the normal Win32.TrojanDownloader.Zlob, but has a different behavior. You can find it at adult sites where it recommends the user to install a Video ActiveX Object to be able to play the desired video clip. If the user chooses to download and run c-setup.exe it will be forwarded to google.com.

Video ActiveX Object Error Fake Alert


Lack of imagination?

by Albin on May 7th, 2008 in Rogues.

A clone of XpAntiVirus has recently been released, named as WinAntiVirus PRO. Those who have been around may remember WinAntiVirus PRO 2006 & 2007.

There are tons of rogue applications out there right now, most use unique names. It was just a matter of time before there started to be name collisions either on purpose or by mistake.

Finally a message to all fake anti-spyware/virus producers:

Do some research before you release new products; you might end up in court with your competitors because of name theft.


Unigray, new Rogue AntiVirus

by LS Anders on March 6th, 2008 in Rogues.

In the last days we have seen a new Rogue AntiVirus program being spread through a trojan. Opening up the program, Unigray AntiVirus, we were met by a somewhat familiar GUI.

UnigrayAntiVirus GUI


Rogue Application Update

by Andy on March 3rd, 2008 in Rogues.

You may have noticed our rogue application definition update last week. It was prompted by the deluge of complaints to our support team about C-NetMedia's AdWareAlert program from people who thought they were buying Lavasoft's AdAware 2007. The update also follows on from the excellent article by Ben Edelman (assisted by our very own Calamity Jane!) on the subject. You can read it here: http://www.benedelman.org/news/021408-1.html.


Spyware Isolator is one of this week's new rogue anti-spyware applications that we have seen here at Lavasoft Research. Its behaviour is typical of standard rogue applications.

 

Application Screenshot

 


x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now