Monday, June 22, 2009

Triple Threat Rogue Treat

Triple Threat Rogue Treat

Lately while analyzing a fake Video ActiveX Object trojan we found that the trojan installs three rogue security applications Antivirus Protection , Malware Doctor and System Security.

Screenshot of Antivirus Protection application

Screenshot of Malware Doctor application

Malware Doctor is a bit old rogue, it has already been reported here and here

Screenshot of System Security application

Further the trojan also hijacks desktop

Stay away from all these rogues.

Bharath M N

Sunday, June 21, 2009

Antivirus Protection

Antivirus Protection

Antivirus Protection is a new rogue security application and a clone of Antivirus'09


Screenshot of Antivirus Protection application

Fake Security Center which was also used by WinDefender 2008 and Antivirus'09


Bharath M N

Contraviro

Contraviro

Contraviro is yet another rogue security application.

Screenshot of Contraviro application


Contraviro removal instructions here

Bharath M N

Terminator 2009

Terminator 2009

Terminator 2009 is a new rogue security application.

Thanks to Malware Database for the heads up.

Screenshot of Terminator 2009 application



Bharath M N

Wednesday, June 17, 2009

Virus Remover Professional

Virus Remover Professional


Virus Remover Professional is a new member of WinSpywareProtect family of rogue security applications.

Screenshot of Virus Remover Professional application

Virus Remover Professional removal instructions here

Bharath M N

Malware Destructor

Malware Destructor

Thanks to S!Ri

Malware Destructor is the new rogue security application from Virusdoctor rogue family.

Screenshot of Malware Destructor rogue security application


Malware Destructor removal instructions here

Bharath M N

Monday, June 15, 2009

Protection System

Protection System

Protection System is the new rogue security application and a clone of CoreGuard Antivirus 2009.

Protection System further attempts to automatically uninstall the following programs

F-Secure
Malwarebytes' Anti-Malware
NOD32
Avast
AntiVir
AVG
Norton Internet Security


Strings in the Installer


Protection System removal instructions here

Bharath M N

Tuesday, June 9, 2009

Antivirus System Pro

Antivirus System Pro

Antivirus System Pro is new rogue security application and a clone of Spyware Protect 2009.

Screenshot of Antivirus System Pro application





Antivirus System Pro removal instructions here

Sites involved:

209.44.111.57 Antivir2009pro com
209.44.111.57 Inetantivir com
209.44.111.57 Inetantivirus com
209.44.111.57 Inetavirus com

Bharath M N

Wednesday, June 3, 2009

XP Deluxe Protector

XP Deluxe Protector

XP Deluxe Protector is a new rogue security application from XP Police Antivirus rogue family.



Screenshot of XP Deluxe Protector application


XP Deluxe Protector removal instructions here

Bharath M N

Unvirex

Unvirex

Thanks to S!Ri

Unvirex is a new rogue security application


Unvirex removal instructions here

Bharath M N

WinBlueSoft

WinBlueSoft

WinBlueSoft is a new rogue security application. This is a clone of WiniGuard rogue security application.

Screenshot of WinBlueSoft application displayed on Bleepingcomputer.com


WinBlueSoft removal instructions here

Bharath M N

Advanced Virus Remover

Advanced Virus Remover

Advanced Virus Remover is a new rogue security application.

Screenshot of Advanced Virus Remover application


Advanced Virus Remover removal instructions here

Bharath M N

Presto TuneUp

Presto TuneUp

Presto TuneUp is a rogue security suite application. Presto TuneUp is a clone of My Supervisor 2009

More info here

Presto TuneUp removal instructions here

Bharath M N