<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Virus/Malware</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/category/security/virusmalware/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 09 Sep 2010 16:45:00 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SafetyGuard</title>
		<link>http://rogueantispyware.blogspot.com/2010/09/safetyguard.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/09/safetyguard.html#comments</comments>
		<pubDate>Thu, 09 Sep 2010 12:36:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeSmoke]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-9192371123158339148</guid>
		<description><![CDATA[SafetyGuard is a rogue security product that pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. It’s the most recent variant in the FakeSmoke Family. VIPRE identified Safe...]]></description>
			<content:encoded><![CDATA[SafetyGuard is a rogue security product that pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. It’s the most recent variant in the FakeSmoke Family. VIPRE identified SafetyGuard and its downloader as VirTool.Win32.Obfuscator.da!a (v) as a result of earlier detections.  We’ve added a new detection to specifically identify it as SafetyGuard.FakeSmoke for user’s convenience.<br /><br /><span style="font-size:130%;"><span style="font-weight: bold;">SafetyGuard online scanner scam<br /></span></span><br />It has nothing to do with dating or searching.<br /><span style="font-size:130%;"><span style="font-weight: bold;"><br /></span></span><a href="http://2.bp.blogspot.com/_1qLRA96ebog/TIjdvhglpZI/AAAAAAAAAWo/pJdmWX2Ra9M/s1600/SafetyGuard_online+scanner.bmp"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 247px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/TIjdvhglpZI/AAAAAAAAAWo/pJdmWX2Ra9M/s400/SafetyGuard_online+scanner.bmp" alt="" id="BLOGGER_PHOTO_ID_5514901552233817490" border="0" /></a><span style="font-size:85%;">(Click graphic to enlarge)</span><br /><br /><span style="font-size:130%;"> <span style="font-weight: bold;">SafetyGuard graphic interface</span></span><br /><br /><a href="http://3.bp.blogspot.com/_1qLRA96ebog/TIjVqoLeS8I/AAAAAAAAAWQ/Hb8I7FjUo-w/s1600/SafetyGuard_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 284px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/TIjVqoLeS8I/AAAAAAAAAWQ/Hb8I7FjUo-w/s400/SafetyGuard_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5514892672031935426" border="0" /></a><span style="font-size:85%;">(Click graphic to enlarge)</span><br /><br /><span style="font-size:130%;"><span style="font-weight: bold;">SafetyGuard installer</span></span><br /><br /><a href="http://1.bp.blogspot.com/_1qLRA96ebog/TIjV2SAVBxI/AAAAAAAAAWY/_Q27Snr9W74/s1600/SafetyGuard2.4.98_Installer.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 308px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/TIjV2SAVBxI/AAAAAAAAAWY/_Q27Snr9W74/s400/SafetyGuard2.4.98_Installer.jpg" alt="" id="BLOGGER_PHOTO_ID_5514892872238040850" border="0" /></a><span style="font-size:85%;">(Click graphic to enlarge)</span><br /><br /><span style="font-weight: bold;font-size:130%;" >SafetyGuard splash screen</span><br /><br /><a href="http://2.bp.blogspot.com/_1qLRA96ebog/TIjV8T8i9lI/AAAAAAAAAWg/FF5d6SvE4HA/s1600/SafetyGuard2.4.98_Splash.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 396px; height: 242px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/TIjV8T8i9lI/AAAAAAAAAWg/FF5d6SvE4HA/s400/SafetyGuard2.4.98_Splash.jpg" alt="" id="BLOGGER_PHOTO_ID_5514892975838262866" border="0" /></a><span style="font-size:85%;">(Click graphic to enlarge)</span><br /><br /><span style="font-size:130%;"><span style="font-weight: bold;">How to remove SafetyGuard:</span></span><br /><br />If  SafetyGuard has infected your pc, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove SafetyGuard from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-9192371123158339148?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/09/safetyguard.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Destructor 2011</title>
		<link>http://rogueantispyware.blogspot.com/2010/09/malware-destructor-2011.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/09/malware-destructor-2011.html#comments</comments>
		<pubDate>Wed, 08 Sep 2010 13:27:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakespyPro]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-1962850101266862528</guid>
		<description><![CDATA[Malware Destructor 2011 is a rogue security product that presents itself as a Microsoft-related "System Security Pack Upgrade."(Click on graphic to enlarge)It pretends to find malicious code on a victim’s machine in order to  frighten him or her into...]]></description>
			<content:encoded><![CDATA[Malware Destructor 2011 is a rogue security product that presents itself as a Microsoft-related "System Security Pack Upgrade."<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/TIePv1DelhI/AAAAAAAAAV4/JyF0dHHyLDo/s1600/MalwareDestructor2011_SystemSecurityPackUpgrade.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/TIePv1DelhI/AAAAAAAAAV4/JyF0dHHyLDo/s400/MalwareDestructor2011_SystemSecurityPackUpgrade.jpg" alt="" id="BLOGGER_PHOTO_ID_5514534320596751890" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />It pretends to find malicious code on a victim’s machine in order to  frighten him or her into purchasing useless software.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/TIeP2Y50Y4I/AAAAAAAAAWA/ACyvbTT-f0A/s1600/MalwareDestructor2011_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 273px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/TIeP2Y50Y4I/AAAAAAAAAWA/ACyvbTT-f0A/s400/MalwareDestructor2011_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5514534433299129218" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/TIeP_PCKu4I/AAAAAAAAAWI/ilgdWqU3gtU/s1600/MalwareDestructor2011_PaymentPage.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 282px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/TIeP_PCKu4I/AAAAAAAAAWI/ilgdWqU3gtU/s400/MalwareDestructor2011_PaymentPage.jpg" alt="" id="BLOGGER_PHOTO_ID_5514534585268616066" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />Malware Destructor 2011 is a clone of  <a href="http://rogueantispyware.blogspot.com/2010/08/av-defender-2011.html">AVDefender2011.FakeSpyPro</a> that was distributed late in August 2010.<br /><br /><span style="font-size:130%;"><span style="font-weight: bold;">How to remove Malware Destructor 2011:</span></span><br /><br />If Malware Destructor 2011 has infected your pc, you should remove it immediately.<a href="http://go.sunbeltsoftware.com/?linkid=405"> Click here to use VIRPE to remove Malware Destructor 2011 from your computer now.</a><br /><br />VIPRE already detected the downloader (VirTool.Win32.Obfuscator.da!a (v)) and module it downloaded.<br /><br />After VIPRE cleans Malware Destructor 2011, a randomly named folder: %APPDATA%\ 72C9D8190B531E44EFA48DBEF901A78F remains. It contains two files which are not executable. One is called enemies-names.txt and contains the fake scan results which the rogue displays. The second file is local.ini which contains the messages that Malware Destructor 2011 displays.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-1962850101266862528?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/09/malware-destructor-2011.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Defender 2011</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/av-defender-2011.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/av-defender-2011.html#comments</comments>
		<pubDate>Tue, 31 Aug 2010 16:37:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakespyPro]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-928702891136832779</guid>
		<description><![CDATA[AV Defender 2011 is a rogue security product that pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. It presents an alarming graphic user interface:(Click on graphic to enla...]]></description>
			<content:encoded><![CDATA[AV Defender 2011 is a rogue security product that pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. It presents an alarming graphic user interface:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/TH0wEyvtGUI/AAAAAAAAAUA/8Hg7XzGfiig/s1600/AVDefender_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 304px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/TH0wEyvtGUI/AAAAAAAAAUA/8Hg7XzGfiig/s400/AVDefender_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5511614377870825794" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />It fakes a “scan” of the potential victim’s machine in order to frighten him or her into making an unwise purchase:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/TH0wSvetFlI/AAAAAAAAAUI/quYq7nJtzh8/s1600/AVDefender_FakeScan.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 304px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/TH0wSvetFlI/AAAAAAAAAUI/quYq7nJtzh8/s400/AVDefender_FakeScan.jpg" alt="" id="BLOGGER_PHOTO_ID_5511614617512384082" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />The “payment” screen, of course, looks very professional. However the rogue vendors have used graphics of “Antivirus Soft” – evidence that they probably are the same distributors of that rogue as well. Here’s our description of<a href="http://rogueantispyware.blogspot.com/2010/02/antivirus-soft.html"> Antivirus Soft from last February. </a><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/TH0whYPnMqI/AAAAAAAAAUQ/n60nNM3I0ag/s1600/AVDefender_PaymentPage.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 253px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/TH0whYPnMqI/AAAAAAAAAUQ/n60nNM3I0ag/s400/AVDefender_PaymentPage.jpg" alt="" id="BLOGGER_PHOTO_ID_5511614868973105826" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />The downloader we found was detected as BehavesLike.Win32.Malware (v) and its executable module was detected as Trojan.Win32.FakeAlert.<br /><br />This rogue is somewhat similar to those in of the FakeSpyPro family, although the downloader actually creates the module.<br /><br />AV Defender 2011 creates the following registry key:<br />HKEY_CURRENT_USERSOFTWARE\AVDEFENDER 2011<br /><br />It also creates the following files on a victim’s machine:<br />%APPDATA%\AVDEFENDER2011<br />%STARTMENU%\AVDEFENDER2011<br /><br />VIPRE detects it as AVDefender2011.FakeSpyPro<br /><br /><span style="font-weight: bold;">How to remove AV Defender 2011:</span><br /><br />If AV Defender 2011 has infected your pc, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove AV Defender 2011 from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-928702891136832779?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/av-defender-2011.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Security Tool 2010</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/advanced-security-tool-2010.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/advanced-security-tool-2010.html#comments</comments>
		<pubDate>Fri, 27 Aug 2010 18:00:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-8413385969619620666</guid>
		<description><![CDATA[Advanced Security Tool 2010 is a rogue security product that downloads itself and  pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. These malicious applications typically ...]]></description>
			<content:encoded><![CDATA[Advanced Security Tool 2010 is a rogue security product that downloads itself and  pretends to find malicious code on a victim’s machine in order to frighten him or her into purchasing this useless application. These malicious applications typically make a fake scan then pop up alarming screens that seem to show malicious code on the victim’s machine. The application requires the victim to pay for the application in order to “clean” the malware.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/THf95hKT2RI/AAAAAAAAAT4/sc0pUhcCqbc/s1600/AvancedSecurityTool2010_GUI.JPG"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 295px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/THf95hKT2RI/AAAAAAAAAT4/sc0pUhcCqbc/s400/AvancedSecurityTool2010_GUI.JPG" alt="" id="BLOGGER_PHOTO_ID_5510151833707075858" border="0" /></a><span style="font-size:85%;">(Click on graphic to enlarge)</span><br /><br />VIPRE detects it as AdvancedSecurityTool2010.<br /><br /><span style="font-weight: bold;">To remove Advanced Security Tool 2010:</span><br /><br />If  Advanced Security Tool 2010 has infected your pc, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove Advanced Security Tool 2010 from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-8413385969619620666?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/advanced-security-tool-2010.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiSpy Safeguard</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html#comments</comments>
		<pubDate>Fri, 27 Aug 2010 12:41:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-4750426039277136170</guid>
		<description><![CDATA[AntiSpy Safeguard is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.(click to enlarge graphic)It re...]]></description>
			<content:encoded><![CDATA[AntiSpy Safeguard is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THey2LD_YJI/AAAAAAAAAS4/saBL7hqaDRw/s1600/AntiSpySafeGuard_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 210px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THey2LD_YJI/AAAAAAAAAS4/saBL7hqaDRw/s400/AntiSpySafeGuard_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5510069312863297682" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THezAQ1NCpI/AAAAAAAAATA/i0QSs0Rh2gA/s1600/Anti_Spy_Safegard_Pay.bmp"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 174px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THezAQ1NCpI/AAAAAAAAATA/i0QSs0Rh2gA/s400/Anti_Spy_Safegard_Pay.bmp" alt="" id="BLOGGER_PHOTO_ID_5510069486210583186" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />One way (there may be others) that AntiSpy Safeguard is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/THezLV3k3KI/AAAAAAAAATI/my25citrTKA/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/THezLV3k3KI/AAAAAAAAATI/my25citrTKA/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5510069676541271202" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues. (AntiSpy Safeguard is lower on list and not shown).<br /><span style="font-size:85%;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THezlwBnvOI/AAAAAAAAATQ/VtNe8MtOe1Q/s1600/FakeOnlinScannerScam.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THezlwBnvOI/AAAAAAAAATQ/VtNe8MtOe1Q/s400/FakeOnlinScannerScam.jpg" alt="" id="BLOGGER_PHOTO_ID_5510070130239323362" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br /><span style="font-weight: bold;">To Remove AntiSpy Safeguard:</span><br /><br />If AntiSpy Safeguard has infected your PC, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove AntiSpy Safeguard from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-4750426039277136170?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiSpy Safeguard</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html#comments</comments>
		<pubDate>Fri, 27 Aug 2010 12:41:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-4750426039277136170</guid>
		<description><![CDATA[AntiSpy Safeguard is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.(click to enlarge graphic)It re...]]></description>
			<content:encoded><![CDATA[AntiSpy Safeguard is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THey2LD_YJI/AAAAAAAAAS4/saBL7hqaDRw/s1600/AntiSpySafeGuard_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 210px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THey2LD_YJI/AAAAAAAAAS4/saBL7hqaDRw/s400/AntiSpySafeGuard_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5510069312863297682" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THezAQ1NCpI/AAAAAAAAATA/i0QSs0Rh2gA/s1600/Anti_Spy_Safegard_Pay.bmp"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 174px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THezAQ1NCpI/AAAAAAAAATA/i0QSs0Rh2gA/s400/Anti_Spy_Safegard_Pay.bmp" alt="" id="BLOGGER_PHOTO_ID_5510069486210583186" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />One way (there may be others) that AntiSpy Safeguard is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/THezLV3k3KI/AAAAAAAAATI/my25citrTKA/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/THezLV3k3KI/AAAAAAAAATI/my25citrTKA/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5510069676541271202" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues. (AntiSpy Safeguard is lower on list and not shown).<br /><span style="font-size:85%;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THezlwBnvOI/AAAAAAAAATQ/VtNe8MtOe1Q/s1600/FakeOnlinScannerScam.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THezlwBnvOI/AAAAAAAAATQ/VtNe8MtOe1Q/s400/FakeOnlinScannerScam.jpg" alt="" id="BLOGGER_PHOTO_ID_5510070130239323362" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br /><span style="font-weight: bold;">To Remove AntiSpy Safeguard:</span><br /><br />If AntiSpy Safeguard has infected your PC, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove AntiSpy Safeguard from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-4750426039277136170?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/antispy-safeguard.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Defense Kit</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/major-defense-kit.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/major-defense-kit.html#comments</comments>
		<pubDate>Thu, 26 Aug 2010 20:46:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-7496216591021882205</guid>
		<description><![CDATA[Major Defense Kit is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.(click to enlarge graphic)It re...]]></description>
			<content:encoded><![CDATA[Major Defense Kit is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THbS029gBPI/AAAAAAAAASY/OcvwzMytuWo/s1600/MajorDefenseKit_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 213px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THbS029gBPI/AAAAAAAAASY/OcvwzMytuWo/s400/MajorDefenseKit_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5509822999682876658" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbS8MuIYeI/AAAAAAAAASg/ANo38nsu3b4/s1600/MajorDefenseKit_PaymentPage.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 253px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THbS8MuIYeI/AAAAAAAAASg/ANo38nsu3b4/s400/MajorDefenseKit_PaymentPage.jpg" alt="" id="BLOGGER_PHOTO_ID_5509823125783077346" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />One way (there may be others) that Major Defense Kit is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbTMfU7BbI/AAAAAAAAASo/wYyScizkHI8/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THbTMfU7BbI/AAAAAAAAASo/wYyScizkHI8/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5509823405655524786" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbTMfU7BbI/AAAAAAAAASo/wYyScizkHI8/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><br /></a><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THbTYQpaCoI/AAAAAAAAASw/iX9C62JpBfU/s1600/MajorDefense_1.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THbTYQpaCoI/AAAAAAAAASw/iX9C62JpBfU/s400/MajorDefense_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5509823607873342082" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br /><span style="font-weight: bold;">To Remove Major Defense Kit:</span><br /><br />If Major Defense Kit has infected your PC, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove Major Defense Kit from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-7496216591021882205?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/major-defense-kit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pest Detector 4.1</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/pest-detector-41.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/pest-detector-41.html#comments</comments>
		<pubDate>Thu, 26 Aug 2010 20:30:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-4732210559231010488</guid>
		<description><![CDATA[Pest Detector 4.1 is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.(click to enlarge graphic)It re...]]></description>
			<content:encoded><![CDATA[Pest Detector 4.1 is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbO8CVcRVI/AAAAAAAAAR4/TIiUUsLLXf4/s1600/PestDetector4.1_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 214px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THbO8CVcRVI/AAAAAAAAAR4/TIiUUsLLXf4/s400/PestDetector4.1_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5509818724948657490" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_1qLRA96ebog/THbPJOGR3DI/AAAAAAAAASA/GMjNoGyWPIA/s1600/PestDetector4.1_PaymentCenter.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 255px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/THbPJOGR3DI/AAAAAAAAASA/GMjNoGyWPIA/s400/PestDetector4.1_PaymentCenter.jpg" alt="" id="BLOGGER_PHOTO_ID_5509818951444585522" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />One way (there may be others) that Pest Detector 4.1 is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THbPVooRe6I/AAAAAAAAASI/BZsJ0pbEVN8/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THbPVooRe6I/AAAAAAAAASI/BZsJ0pbEVN8/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5509819164724919202" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues. (Pest Detector is lower on the screen and not shown.)<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_1qLRA96ebog/THbPzyjmgMI/AAAAAAAAASQ/u0Kg-GjBsgw/s1600/FakeOnlinScannerScam.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/THbPzyjmgMI/AAAAAAAAASQ/u0Kg-GjBsgw/s400/FakeOnlinScannerScam.jpg" alt="" id="BLOGGER_PHOTO_ID_5509819682785755330" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br /><span style="font-weight: bold;">To Remove Pest Detector 4.1:</span><br /><br />If Pest Detector 4.1 has infected your PC, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove Pest Detector 4.1 from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-4732210559231010488?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/pest-detector-41.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peak Protection 2010</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/peak-protection-2010.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/peak-protection-2010.html#comments</comments>
		<pubDate>Thu, 26 Aug 2010 20:10:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-5853128080792130529</guid>
		<description><![CDATA[Peak Protection 2010 is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code. It requires you to pay for ...]]></description>
			<content:encoded><![CDATA[Peak Protection 2010 is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code. It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbKo6JhVoI/AAAAAAAAARg/BjvhkweO7HY/s1600/PeakProtection2010_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 209px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THbKo6JhVoI/AAAAAAAAARg/BjvhkweO7HY/s400/PeakProtection2010_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5509813998287148674" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)<br /></span><br />One way (there may be others) that Peak Protection 2010 is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_1qLRA96ebog/THbK8L63xXI/AAAAAAAAARo/vZrjGvyuL4Y/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://4.bp.blogspot.com/_1qLRA96ebog/THbK8L63xXI/AAAAAAAAARo/vZrjGvyuL4Y/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5509814329475057010" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_1qLRA96ebog/THbLEj0STyI/AAAAAAAAARw/fo05Qz3YHxU/s1600/PeakProtection_1.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://1.bp.blogspot.com/_1qLRA96ebog/THbLEj0STyI/AAAAAAAAARw/fo05Qz3YHxU/s400/PeakProtection_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5509814473328840482" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br /><span style="font-weight: bold;">To Remove Peak Protection:</span><br /><br />If Peak Protection 2010 has infected your PC, you should remove it immediately. <a href="http://go.sunbeltsoftware.com/?linkid=405">Click here to use VIRPE to remove Peak Protection 2010 from your computer now.</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-5853128080792130529?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/peak-protection-2010.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Cross Antivirus</title>
		<link>http://rogueantispyware.blogspot.com/2010/08/red-cross-antivirus.html</link>
		<comments>http://rogueantispyware.blogspot.com/2010/08/red-cross-antivirus.html#comments</comments>
		<pubDate>Thu, 26 Aug 2010 19:32:00 +0000</pubDate>
		<dc:creator>Tom Kelchner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Rouge Software]]></category>
		<category><![CDATA[Virus/Malware]]></category>
		<category><![CDATA[FakeRean]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">tag:blogger.com,1999:blog-1641410171038712287.post-6972283931700729842</guid>
		<description><![CDATA[Red Cross Antivirus is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code. It requires you to pay for t...]]></description>
			<content:encoded><![CDATA[Red Cross Antivirus is in the FakeRean family of rogue security products. VIPRE detects it as Trojan.Win32.Generic.pak!cobra. Like all rogues, it does a fake scan of your computer then tells you it has found malicious code. It requires you to pay for the fake software before it “cleans” your machine of the fictitious infections.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_1qLRA96ebog/THbB3z9qCbI/AAAAAAAAARI/xhHE9-RGKO4/s1600/RedCrossAntivirus_GUI.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 212px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/THbB3z9qCbI/AAAAAAAAARI/xhHE9-RGKO4/s400/RedCrossAntivirus_GUI.jpg" alt="" id="BLOGGER_PHOTO_ID_5509804358720162226" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />One way (there may be others) that Red Cross Antivirus is delivered is through a phony “Microsoft Security Essentials Alert” which is displayed by a Trojan.<br /><br />Basically, it mimics the idea of VirusTotal, (http://www.virustotal.com/ )  a site which enables you to see how 40 legitimate security companies identify a sample of malicious code that you submit.<br /><br />The downloader copies itself into multiple folders under different names.  After five to 15 minutes it generates a fake alert pop-up window:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_1qLRA96ebog/THbCPyQSEsI/AAAAAAAAARQ/a5oSzs0v80c/s1600/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 211px;" src="http://2.bp.blogspot.com/_1qLRA96ebog/THbCPyQSEsI/AAAAAAAAARQ/a5oSzs0v80c/s400/MicrosoftSecurityEssentialsAlert_FakeAlert.jpg" alt="" id="BLOGGER_PHOTO_ID_5509804770578272962" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />If you click ANY of the four buttons on the scary “Potential threat details” screen, it takes you to a web site that shows you how different anti-malware products allegedly identify the malware that is (not really) on your computer. It includes a long list of legitimate ones, which, oddly enough find no infection on your machine.<br /><br />However, the display shows that some of them -- all of which are rogues -- have identified malicious files. They have a “free install” button listed next to their names. Clicking on the buttons installs the rogues.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_1qLRA96ebog/THbCcBY-ppI/AAAAAAAAARY/cXUgTeRzM5Y/s1600/RedCrossAntivirus_1.jpg"><img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://3.bp.blogspot.com/_1qLRA96ebog/THbCcBY-ppI/AAAAAAAAARY/cXUgTeRzM5Y/s400/RedCrossAntivirus_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5509804980799710866" border="0" /></a><span style="font-size:85%;">(click to enlarge graphic)</span><br /><br />To Remove Red Cross Antivirus:<br /><br />If Red Cross Antivirus has infected your PC, you should remove it immediately. Click here to use VIRPE to removeRed Cross Antivirus from your computer now.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1641410171038712287-6972283931700729842?l=rogueantispyware.blogspot.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://rogueantispyware.blogspot.com/2010/08/red-cross-antivirus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
