Tuesday, October 30, 2012
Microsoft Essentials Security Pro 2013
Posted by Bharath M Narayan at 11:36 AM View Comments Links to this post
Monday, October 1, 2012
The Return of Chameleon Rogue
The Return of Chameleon Rogue
31.184.244.59
31.184.244.62
31.184.244.63
Stay away from these IP's.
Posted by Bharath M Narayan at 5:55 PM View Comments Links to this post
Thursday, August 30, 2012
Win 8 Security System
Win 8 Security System
Today we saw a new rogue security application called Win 8 Security System being distributed.
This rogue belongs to Braviax/FakeRean rogue family, which is well known for their series of Chameleon Rogue
When tested the fake/scare scanner page was pushing legitimate Windows 7 Calc.exe
Following is a small list of other Rogue security applications connected with the same IP as Win 8 Security System. You might also notice that these rogues comes with the brand name Windows Innovation Inc
Sites associated with the rogue campaign:
31.184.244.59 great-antispy2012.com
31.184.244.59 allwinsecuritysys.com
31.184.244.59 st777st.com
31.184.244.59 win8sec.com
31.184.244.59 gersmsfn.com
Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 10:39 PM View Comments Links to this post
Wednesday, November 30, 2011
From Porn to Fake AV
While looking at this rogue campaign, we noticed the following. A usual fake porn site asking the user to download the fake codec to view the video
On their website we saw template background images of AV's such as Avira, Kaspersky and Norton which are used in this campaign.
Unlike old rogue's what we have seen this campaign is a bit different. The malware file (fake codec) doesn't contain any GUI component in it.
You might ask how does it perform a fake/scare scan which is a crucial part of the rogue application. Well, to achieve this the campaign has used a very simple solution. Open Internet explorer and display a webpage, carry on the fake scanning stuff online through this web page.
The web page opened by the malware uses one of the above mentioned template background image and mimics a scan.
The final step in any rogue campaign is to make the user pay for the junk. Interestingly this campaign doesn't push the user to buy their product. (so far)
Posted by Bharath M Narayan at 12:01 AM View Comments Links to this post
Tuesday, July 12, 2011

Facebook
The best page I saw for quite sometime! now ppl get back to work :))
And this happens only with my account! Now that's cool.. :))
Cheers
Posted by Bharath M Narayan at 4:52 PM View Comments Links to this post
Wednesday, December 8, 2010
Security Shield
Security Shield is the latest rogue that replaces the long running Security Tool rogue campaign.

Security Shield removal instructions here
Posted by Bharath M Narayan at 3:54 PM View Comments Links to this post
Three new rogues
PC optimizer 2010, Privacy Corrector, Privacy Guard 2010 are the latest rogue security applications that has replaced ThinkPoint rogue security application.



You can find the removal instructions here
Bharath M N
Posted by Bharath M Narayan at 3:29 PM View Comments Links to this post
Friday, November 12, 2010
Internet Security Suite
Internet Security Suite is the latest rogue security application from Virusdoctor rogue family.

More info here
Bharath M N
Posted by Bharath M Narayan at 5:21 PM View Comments Links to this post
Monday, November 8, 2010
Security Inspector 2010
Security Inspector 2010 is a new rogue security application from Unvirex rogue family.




Security Inspector 2010 removal instructions here
Bharath M N
Posted by Bharath M Narayan at 6:55 AM View Comments Links to this post
Sunday, November 7, 2010
Security Essentials 2011
Security Essentials 2011 is a new rogue security application from Advanced Virus Remover rogue family. This rogue replaces Security Essentials 2010 rogue security application.

Security Essentials 2011 removal instructions here
Bharath M N
Posted by Bharath M Narayan at 3:36 PM View Comments Links to this post











