| 

Fake AV & Talking With The Enemy

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 2 min
  • Word Count: 349 words

Fake antivirus software (a.k.a misleading applications or rogue antivirus) is big business nowadays with Symantec reporting 43 million installation attempts from over 250 distinct programs between July 1, 2008, to June 30, 2009. With fake AV software costing the victim anywhere from $30 to $100, this is a lucrative earner for criminals. Over time Symantec has observed various social engineering tactics being used to try and entice victims to hand over their money in this scam. The fake antivirus software known as Live PC Care has now gone as far as offering live online support to potential victims. Once a victim has installed Live PC Care onto their system via a system exploit or social engineering tactics, they are presented with the screen below falsely informing them that their system is riddled with viruses. Any suspicious computer user might wonder what this software is and where exactly it came from. To alleviate doubt and to aid with the whole scam, the designers of Live PC Care have added a yellow online support button in the top, right-hand corner of the fake AV software. ...

Continue Reading Fake AV & Talking With The Enemy

New Rogue: Advanced Defender

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 1 min
  • Word Count: 131 words

Advanced Defender is fake security software that tricks people into thinking it’s legitimate antispyware software in hopes they will pay for the product. Advanced Defender is a potentially dangerous and extremely frustrating PC infection that should be removed immediately. If Advanced Defender has infected your computer you may notice the following symptoms: System scans that report numerous infections, yet requires purchase of Advanced Defender before it will remove the infections (These are fictitious scan results) Alerts and Pop-Up system warnings stating the PC is infected and recommend purchase of Advanced Defender (These warnings are fake) Web browser redirecting to random websites (these websites are owned by cyber thieves and will further infect your PC) Advanced Defender will prevent other programs from opening, stating they are infected (The programs are not infected)

Continue Reading New Rogue: Advanced Defender

Take Care Before Valentine: Cupid Struck

  • Post author: Omid Farhang
  • Post published: February 11, 2010
  • Reading Time: 1 min
  • Word Count: 188 words

It’s just a few more days before Valentine’s Day. As most people now are already preparing their celebration, malware authors are also getting ready to use this popular event to target users with their malicious intent. Here’s one example of a malicious file (2077ed17f0ad92dafb8fb7601570e06580e4b7f1) we’ve seen recently: Upon execution, it drops the following picture file greeting: Note: It seems that the malware writers are using valid images from legitimate Web sites. ...

Continue Reading Take Care Before Valentine: Cupid Struck

New Rogue: SafePcAV

  • Post author: Omid Farhang
  • Post published: February 8, 2010
  • Reading Time: 1 min
  • Word Count: 71 words

The creators behind the rogue antispyware appliaction WiniGuard have released yet another clone of their software. This one is called SafePcAV. SafePcAV spreads by showing fake online scanners. Once installed it will show hundreds of false infections. To remove these infections it requires the user to pay and license the software. If your computer is infected with this you must remove it soon, Click Here to learn how to remove it. ...

Continue Reading New Rogue: SafePcAV

Phony Firefox update comes with Hotbar adware

  • Post author: Omid Farhang
  • Post published: February 7, 2010
  • Reading Time: 2 min
  • Word Count: 231 words

Our good friends at Broomfield, Colo., security firm eSoft have found an interesting scam to trick Internet users into installing the Hotbar adware: a fake Firefox download site. The eSoft researchers are theorizing that an affiliate of Pinball Publisher Network (PPB). is responsible. Pinball bought the Zango assets after that pestilent operation failed last spring. However Sunbelt Software Spyware Research Manager Eric Howes did some more digging and found that PPN offers the download file on a site they own so affiliates can send customers victims there for downloads. ...

Continue Reading Phony Firefox update comes with Hotbar adware

Trojan code sneaks into two Mozilla add-ons

  • Post author: Omid Farhang
  • Post published: February 5, 2010
  • Reading Time: 1 min
  • Word Count: 159 words

Mozilla yesterday posted a notice on its AMO blog (that’s an acronym for their add-on site addons.mozilla.org) that two add-ons have been found infected with Trojan code: Sothink Web Video Downloader v. 4.0 and all versions of Master Filer. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen and Master Filer contained Win32.Bifrose. According to the blog, Masterfiler was downloaded 600 times before it was removed from the site Jan. 25 and Sothink was downloaded more than 4,000 times before it was removed Feb. 2. ...

Continue Reading Trojan code sneaks into two Mozilla add-ons

It’s lame ransomware, but it could fool somebody

  • Post author: Omid Farhang
  • Post published: February 4, 2010
  • Reading Time: 1 min
  • Word Count: 62 words

Found this little gem today. It’s distributed with other malware, cracks and drive-by downloads. It purports to be a security warning from your Windows operating system. Notice the “Visa, MasterCard, etc” – it doesn’t even bother to list all the cards it accepts. The really cool thing about it is that it takes FAKE credit card numbers as well as real ones!

Continue Reading It’s lame ransomware, but it could fool somebody

Anatomy of a free Starbucks gift card scam

  • Post author: Omid Farhang
  • Post published: February 4, 2010
  • Reading Time: 3 min
  • Word Count: 517 words

With virus and spam outbreaks, analysts needs to keep their nerves to analyze the situation and proceed to deal with the new threat. So, I wasn’t expected to be surprised by my friends’ actions on facebook this past weekend. It started innocently enough, as a post about getting a Free $25 Starbucks gift card for joining a particular group. The first person to join the group from my friends list happens to work for a non-profit organization helping young people. So, I expected the young people on his “friends list” to join this group shortly. ...

Continue Reading Anatomy of a free Starbucks gift card scam

Microsoft Support informs you


  • Post author: Omid Farhang
  • Post published: February 4, 2010
  • Reading Time: 1 min
  • Word Count: 163 words

Since yesterday, our lab has detected a flood of email messages that seem to contain a Microsoft Update, but it’s actually malware. We’ve seen around 3,000 in a few hours. The message is like the following: This email, which seems to have been sent by the Microsoft Support team, informs you that a new security update for Outlook/Outlook Express has been released. It’s a critical update, so it’s better to install it as soon as possible. ...

Continue Reading Microsoft Support informs you


New Rogue: MyPcSecure

  • Post author: Omid Farhang
  • Post published: February 1, 2010
  • Reading Time: 1 min
  • Word Count: 14 words

MyPcSecure is the latest rogue anti-spyware application and a clone from the WiniGuard family.

Continue Reading New Rogue: MyPcSecure