| 

New Rogue: SecurePcAv

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 1 min
  • Word Count: 110 words

SecurePcAv is a phony antivirus program that has been infecting PCā€™s across the interwebs in recent days. If your PC is infected with SecurePcAv you will most likely experience the following: Fake system scans that report numerous infections and refuses to remove the supposed infections until you buy the phony software. Alerts and warnings stating the PC is under attack or unprotected and recommends you buy the phony software. Other software will not work, when attempting to open programs a warning stating the program is infected appears and the software is closed. Web browser hijacking, redirecting the user to malicious websites or showing false security warnings on sites like Google.com.

Continue Reading New Rogue: SecurePcAv

New Rogue: Paladin Antivirus

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 1 min
  • Word Count: 180 words

Paladin Antivirus is a phony security program, designed to rip people off. Paladin Antivirus tricks people into thinking they are downloading a legit antivirus software, then continually displays false security alerts and warnings followed up with a requests for users to buy or register the software. Once a computer becomes infected with Paladin Antivirus it will instantly begin a system scan and will report multiple infections. Paladin Antivirus will refuse to remove any of these supposed infections until the user buys or ā€œregistersā€ the software. Do not fall for this scam. ...

Continue Reading New Rogue: Paladin Antivirus

Between a PoC and a Hard Place

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 491 words

Several reports have been published detailing a Blackberry proof of concept (PoC) exploit calledĀ txsBBSpyĀ that was recently presented at a security conference. Although it may not have been the aim of the original presenter, some reports have framed the PoC as being able to exploit so-called vulnerabilities that the writers believe to be present in the Blackberry platform. The ā€œvulnerabilitiesā€ involve secretly forwarding incoming emails, locating devices by way of their GPS capabilities, eavesdropping on conversations by surreptitiously turning on microphones, and other such nefarious behavior. ...

Continue Reading Between a PoC and a Hard Place

Interview with a Nigerian 419 scammer

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 486 words

Bruce Schneier, in his blog Schneier on SecurityĀ http://www.schneier.com/Ā drew attention to this great interview with an ex-Nigerian-419 scammer on theĀ Scam-Detective site. Itā€™s a fairly long piece and gives a pretty good view of the Nigerian scam industry run by organized crime, how it sucks in young people who have good computer and English skills and pays them a huge amount of money ($75,000 per year in this case) to scam victims they view as white, greedy and rich. ...

Continue Reading Interview with a Nigerian 419 scammer

Fake AV & Talking With The Enemy

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 2 min
  • Word Count: 349 words

Fake antivirus software (a.k.a misleading applications or rogue antivirus) is big business nowadays withĀ Symantec reportingĀ 43 million installation attempts from over 250 distinct programs between July 1, 2008, to June 30, 2009. With fake AV software costing the victim anywhere from $30 to $100, this is a lucrative earner for criminals. Over time Symantec has observed various social engineering tactics being used to try and entice victims to hand over their money in this scam. The fake antivirus software known as Live PC Care has now gone as far as offering live online support to potential victims.Ā Once a victim has installed Live PC Care onto their system via a system exploit or social engineering tactics, they are presented with the screen below falsely informing them that their system is riddled with viruses. Any suspicious computer user might wonder what this software is and where exactly it came from. To alleviate doubt and to aid with the whole scam, the designers of Live PC Care have added a yellow online support button in the top, right-hand corner of the fake AV software. ...

Continue Reading Fake AV & Talking With The Enemy

New Rogue: Advanced Defender

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 1 min
  • Word Count: 131 words

Advanced Defender is fake security software that tricks people into thinking itā€™s legitimate antispyware software in hopes they will pay for the product. Advanced Defender is a potentially dangerous and extremely frustrating PC infection that should be removed immediately. If Advanced Defender has infected your computer you may notice the following symptoms: System scans that report numerous infections, yet requires purchase of Advanced Defender before it will remove the infections (These are fictitious scan results) Alerts and Pop-Up system warnings stating the PC is infected and recommend purchase of Advanced Defender (These warnings are fake) Web browser redirecting to random websites (these websites are owned by cyber thieves and will further infect your PC) Advanced Defender will prevent other programs from opening, stating they are infected (The programs are not infected)

Continue Reading New Rogue: Advanced Defender

A Perfect Valentineā€™s Day

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 535 words

Planning a romantic Valentineā€™s Day for your loved one? Is there is no end to all that you can do to add even more sparkle this dreamy day? Perhaps a bottle of wine, flowers, or a lovely gift to impress him/herā€”and if you arenā€™t with anyone, there are even dating services available that provide you with options to meet a date. As Dermot Harnett mentioned inĀ A Brilliant Proposal: Stay Away from Valentineā€™s Day Spam!, for spammers, Valentineā€™s Day is a great target. Weā€™ve observed several spam email message styles related to this upcoming event. Gift options, flower delivery, dating service, med spam to spice up your relationship, and much more. Here are some common header lines that Symantec has tracked relating to Valentineā€™s Day: ...

Continue Reading A Perfect Valentineā€™s Day

Take Care Before Valentine: Cupid Struck

  • Post author: Omid Farhang
  • Post published: February 11, 2010
  • Reading Time: 1 min
  • Word Count: 188 words

Itā€™s just a few more days before Valentineā€™s Day. As most people now are already preparing their celebration, malware authors are also getting ready to use this popular event to target users with their malicious intent. Hereā€™s one example of a malicious file (2077ed17f0ad92dafb8fb7601570e06580e4b7f1) weā€™ve seen recently: Upon execution, it drops the following picture file greeting: Note: It seems that the malware writers are using valid images from legitimate Web sites. ...

Continue Reading Take Care Before Valentine: Cupid Struck

Rogue trying to look like Avira anti-virus

  • Post author: Omid Farhang
  • Post published: February 11, 2010
  • Reading Time: 1 min
  • Word Count: 184 words

Jerome Segura at ParetoLogic blogged about this yesterday: a rogue security product with a web page that tries to imitate that of the German AV company Avira (check out the red umbrella and the type face.) Hmmm. If this company has been providing ā€œ20 Years of Total Protectionā€ how come its web site was just registered last year and why was it registered by a proxy service? The fake: ...

Continue Reading Rogue trying to look like Avira anti-virus

New Rogue: SafePcAV

  • Post author: Omid Farhang
  • Post published: February 8, 2010
  • Reading Time: 1 min
  • Word Count: 71 words

The creators behind the rogue antispyware appliaction WiniGuard have released yet another clone of their software. This one is called SafePcAV. SafePcAV spreads by showing fake online scanners. Once installed it will show hundreds of false infections. To remove these infections it requires the user to pay and license the software. If your computer is infected with this you must remove it soon, Click Here to learn how to remove it. ...

Continue Reading New Rogue: SafePcAV