Jump to content

Rogue security software: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
PedroDaGr8 (talk | contribs)
Partial list of rogue software: Added refs for MalwareBell - Perfect Defender 2009
PedroDaGr8 (talk | contribs)
Partial list of rogue software: Added refs for PersonalAntispy Free - SpywareBot - Removed plus4scan and others as they are sites not programs
Line 39: Line 39:
{{Col-break}}
{{Col-break}}
* [[Advanced Cleaner]]<ref>[http://www.precisesecurity.com/blogs/2007/08/09/advanced-cleaner/ Precise Security - Advanced Cleaner]</ref>
* [[Advanced Cleaner]]<ref>[http://www.precisesecurity.com/blogs/2007/08/09/advanced-cleaner/ Precise Security - Advanced Cleaner]</ref>
* [[AlfaCleaner]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm Rogue List - AlfaCleaner]</ref>
* [[AlfaCleaner]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm Spyware Warrior - AlfaCleaner]</ref>
* [[AntiSpyCheck 2.1]]<ref>[http://www.bleepingcomputer.com/uninstall/10802/AntiSpyCheck-2.1.0.html BleepingComputer - AntiSpyCheck 2.1]</ref>
* [[AntiSpyCheck 2.1]]<ref>[http://www.bleepingcomputer.com/uninstall/10802/AntiSpyCheck-2.1.0.html BleepingComputer - AntiSpyCheck 2.1]</ref>
* [[AntiSpyStorm]]<ref>[http://www.bleepingcomputer.com/uninstall/5779/AntispyStorm-1.01.0027.html BleepingComputer - AntispyStorm]</ref>
* [[AntiSpyStorm]]<ref>[http://www.bleepingcomputer.com/uninstall/5779/AntispyStorm-1.01.0027.html BleepingComputer - AntispyStorm]</ref>
* [[AntiSpywareExpert]]<ref>[http://antivirus.about.com/od/roguescanners/p/antispyexpert.htm About.com AntiSPywareExpert]</ref>
* [[AntiSpywareExpert]]<ref>[http://www.2-spyware.com/remove-antispywareexpert.html 2-Spyare - AntiSpywareExpert]</ref>
* [[AntiSpywareMaster]]<ref>[http://www.2-spyware.com/remove-antispywaremaster.html 2-Spyware - AntiSpywareMaster]</ref>
* [[AntiSpywareMaster]]<ref>[http://www.2-spyware.com/remove-antispywaremaster.html 2-Spyware - AntiSpywareMaster]</ref>
* [[AntiSpywareSuite]]<ref>[http://www.precisesecurity.com/blogs/2008/07/03/spyshredder-professional-antispyware-suite/ Precise Security - AntiSpywareSuite]</ref>
* [[AntiSpywareSuite]]<ref>[http://www.precisesecurity.com/blogs/2008/07/03/spyshredder-professional-antispyware-suite/ Precise Security - AntiSpywareSuite]</ref>
Line 53: Line 53:
* [[MS Antivirus|Antivirus 360]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-360 BleepingComputer - Antivirus360]</ref>
* [[MS Antivirus|Antivirus 360]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-360 BleepingComputer - Antivirus360]</ref>
* [[MS Antivirus|Antivirus Pro 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-pro-2009 BleepingComputer - AntivirusPro2009]</ref>
* [[MS Antivirus|Antivirus Pro 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-pro-2009 BleepingComputer - AntivirusPro2009]</ref>
* [[AntiVirus Gold]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-032415-1558-99 Symantec]</ref>
* [[AntiVirus Gold]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-032415-1558-99 Symantec - AntiVirus Gold]</ref>
* [[MS Antivirus|Antivirus Master]]<ref>[http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-master BleepingComputer - Antivirus Master]</ref>
* [[MS Antivirus|Antivirus Master]]<ref>[http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-master BleepingComputer - Antivirus Master]</ref>
* [[MS Antivirus|Antivirus XP 2008]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2 Symantec]</ref>
* [[MS Antivirus|Antivirus XP 2008]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2 Symantec - Antivirus XP]</ref>
* [[Avatod Antispyware 8.0]] <ref>[http://www.2-spyware.com/remove-avatod-antispyware.html 2-Spyware - Avatod Antispyware]</ref>
* [[Avatod Antispyware 8.0]] <ref>[http://www.2-spyware.com/remove-avatod-antispyware.html 2-Spyware - Avatod Antispyware]</ref>
* [[Awola]]<ref>[http://www.spywareremove.com/removeAwola.html SpywareRemove - Awola]</ref>
* [[Awola]]<ref>[http://www.spywareremove.com/removeAwola.html SpywareRemove - Awola]</ref>
Line 81: Line 81:
* [[Malware Defender]] (not to be confused with the HIPS firewall of the same name)<ref>[http://www.2-spyware.com/remove-malware-defender-2009.html 2-Spyware - Malware Defender]</ref>
* [[Malware Defender]] (not to be confused with the HIPS firewall of the same name)<ref>[http://www.2-spyware.com/remove-malware-defender-2009.html 2-Spyware - Malware Defender]</ref>
* [[MS Antivirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-ms-antivirus BleepingComputer - MS Antivirus]</ref>
* [[MS Antivirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-ms-antivirus BleepingComputer - MS Antivirus]</ref>
* [[MS AntiSpyware 2009]]<ref>http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009</ref>
* [[MS AntiSpyware 2009]]<ref>http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009]</ref>
* [[MaxAntiSpy]]<ref>[http://www.2-spyware.com/remove-maxantispy.html 2-Spyware - MaxAntispy]</ref>
* [[MaxAntiSpy]]<ref>[http://www.2-spyware.com/remove-maxantispy.html 2-Spyware - MaxAntispy]</ref>
* [[Netcom3 Cleaner]]<ref>[http://www.sunbeltsecurity.com/ThreatDisplay.aspx?name=Netcom3%20Cleaner&tid=417577&cs=53B10F8781B13BE938E57A2E7FBD042A Sunbelt Security - Netcom3 Cleaner]</ref>
* [[Netcom3 Cleaner]]<ref>[http://www.sunbeltsecurity.com/ThreatDisplay.aspx?name=Netcom3%20Cleaner&tid=417577&cs=53B10F8781B13BE938E57A2E7FBD042A Sunbelt Security - Netcom3 Cleaner]</ref>
Line 88: Line 88:
* [[PC Clean Pro]] <ref>[http://www.malwarebytes.org/forums/index.php?showtopic=5252 MalwareBytes - PC Clean Pro]</ref>
* [[PC Clean Pro]] <ref>[http://www.malwarebytes.org/forums/index.php?showtopic=5252 MalwareBytes - PC Clean Pro]</ref>
* [[PC Privacy Cleaner]]<ref>[http://www.spywareremove.com/removePCPrivacyCleaner.html SpywareRemove - PC Privacy Cleaner]</ref>
* [[PC Privacy Cleaner]]<ref>[http://www.spywareremove.com/removePCPrivacyCleaner.html SpywareRemove - PC Privacy Cleaner]</ref>
* [[PC SpeedScan Pro]] (distributed by [[FinallyFast.com]]) (Rogueness is questionable)
* [[PC SpeedScan Pro]] (distributed by [[FinallyFast.com]], Rogueness is questionable)
* [[PestTrap]] <ref>[http://www.bleepingcomputer.com/forums/topic58391.html BleepingComputer - PestTrap]</ref>
* [[PestTrap]] <ref>[http://www.bleepingcomputer.com/forums/topic58391.html BleepingComputer - PestTrap]</ref>
* [[PerfectCleaner]]<ref>[http://www.malwarebytes.org/roguenet.php?id=266 MalwareBytes - PerfectCleaner]</ref>
* [[PerfectCleaner]]<ref>[http://www.malwarebytes.org/roguenet.php?id=266 MalwareBytes - PerfectCleaner]</ref>
* [[Perfect Defender 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-perfect-defender-2009 BleepingComputer - Perfect Defender 2009]</ref>
* [[Perfect Defender 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-perfect-defender-2009 BleepingComputer - Perfect Defender 2009]</ref>
* [[PersonalAntiSpy Free]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-personalantispy BleepingComputer - PersonalAntiSpy Free]</ref>
* [[PersonalAntiSpy Free]]
* [[PAL Spyware Remover]]<ref>http://www.spywarewarrior.com/rogue_anti-spyware.htm SpywareWarrior - PAL Spyware Remover]</ref>
* [[PAL Spyware Remover]]
* [[PCPrivacy Tools]]<ref>[http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453116863 ComputerAssociates - PCPrivacy Tools]</ref>
* [[PCPrivacytool]]
* [[PC Antispyware]]<ref>[http://www.spywareremove.com/removePCAntispyware.html SpywareRemove - PC Antispyware]</ref>
* [[PC-Antispyware]]
* PSGuard<ref>[http://www.spywareremove.com/removePSGuard.html SpywareRemove - PSGuard]</ref>
* [[Plus4scan.com]]
* [[Rapid AntiVirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-rapidantivirus BleepingComputer - Rapid AntiVirus]</ref>
* [[Premium-Antivirus-Defence]]
* [[Real AntiVirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-real-antivirus BleepingComputer - Real Antivirus]</ref>
* PSGuard
* [[Registry Great]]<ref>[http://www.precisesecurity.com/threats/registry-great/ Precise Security - Registry Great]</ref>
* [[Rapid AntiVirus]]
* [[SaliarAR]]<ref>[http://www.emsisoft.com/en/malware/?Adware.Win32.SaliarAR Emsi Soft - SaliarAR]</ref>
* [[Real AntiVirus]]
* [[SecurePCCleaner]]<ref>[http://www.spywareremove.com/removeSecurePCCleaner.html SpywareRemove - SecurePCCleaner]</ref>
* [[Registry Great]]
* [[Security Toolbar 7.1]]<ref>[http://www.precisesecurity.com/blogs/2007/05/24/adware-security-toolbar-71/ Precise Security - Security Toolbar 7.1]</ref>
* [[SaliarAR]]
* [[Smart Antivirus 2009]]<ref>[http://www.2-spyware.com/remove-smart-antivirus-2009.html 2-Spyware - Smart Antivirus 2009]</ref>
* [[SecurePCCleaner]]
* [[Security toolbar 7.1]]
* [[Smart Antivirus 2008]]
* [[Smart Antivirus 2009]]
* [[SpyAxe]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-123015-4116-99 Symantec]</ref>
* [[SpyAxe]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-123015-4116-99 Symantec]</ref>
* [[Spy Away]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm Spyware Warrior - Spy Away]</ref>
* [[Spy Away]]
* [[SpyCrush]]<ref>[http://www.bleepingcomputer.com/forums/topic80749.html BleepingComputer - SpyCrush]</ref>
* [[SpyCrush]]
* [[Spydawn]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053116-5727-99 Symantec]</ref>
* [[Spydawn]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053116-5727-99 Symantec - SpyDawn]</ref>
* [[SpyGuarder]]<ref>[http://www.precisesecurity.com/threats/spyguarder/ Precise Security - SpyGuarder]</ref>
* [[SpyGuarder]]
* [[SpyHeal]] (a.k.a SpyHeals & VirusHeal)<ref>[http://www.bleepingcomputer.com/forums/topic58129.html BleepingComputer - SpyHeal]</ref>
* [[SpyHeal]]
* [[SpyMarshal]]<ref>[http://www.411-spyware.com/spymarshal 411-Spyware - SpyMarshal]</ref>
* [[SpyMarshal]]
* [[Spylocked]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053117-1026-99 Symantec]</ref>
* [[Spylocked]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053117-1026-99 Symantec - Spylocked]</ref>
* [[SpySheriff]] <ref name="Symantec"/>
* [[SpySheriff]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-122910-4625-99 Symantec - SpySheriff]</ref>
* [[SpySpotter]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-061611-4947-99 Symantec - SpySpotter]</ref>
* [[SpySpotter]]
* [[SpywareBot]] ([[Spybot - Search & Destroy]] knockoff)
* [[SpywareBot]] ([[Spybot - Search & Destroy]] knockoff)<ref>[http://www.2-spyware.com/review-spywarebot.html 2-Spyare - SpywareBot]</ref>
{{Col-break}}
{{Col-break}}
* [[Spyware Cleaner]]
* [[Spyware Cleaner]]

Revision as of 00:22, 18 April 2009

Rogue security software is software that uses malware (malicious software) or malicious tools to advertise or install itself or to force computer users to pay for removal of nonexistent malware. Rogue software will often install a trojan horse to download a trial version, or it will execute other unwanted actions. The first and most comprehensive study of rogue and real antispyware programs was carried out by Eric L. Howes.[1]

Installation

The main goal of rogue software makers is to install and sell their product. In order to attempt to install their program, fake Windows dialog boxes and other browser pop-ups are often displayed attempting to entice the user to click on them. Most of the time, they will display a message such as "WARNING! Your computer is infected with Spyware/Adware/Viruses! Buy [software name] to remove it!", a variant of which will say "Click OK to scan your system" instead of asking the user to outright buy the software. Another variant on this method involves telling the user their "Computer/Internet Connection/OS is not optimized and to Click Here to scan now". Usually, when the dialog box's OK button is clicked, this will direct the user to a malicious website, which will install the program. Sometimes, even clicking the upper right hand X button to close the dialog box will produce the same effect. (Pressing Alt+F4 or using Task Manager with Ctrl-Alt-Delete can circumvent that trick). Some software, like SpyAxe, will automatically download the trial version without any user action, in a process know as a drive-by installation. Along with the installation of the rogue programs, many sites now attempt to install multiple trojans at one time by downloading what is called a dropper first, which then loads a variety of malware to the computer.

Tactics

Once installed, the programs rely on several tactics to attempt to entice the user into purchasing a "full" version. These include false positives, downloaded malware, false security alerts and locking various aspects of the system to prevent user changes.

False positives

A common method used by rogue security software makers use is that of intentional false positives. A false positive is a fake or false malware detection in a computer scan. This attempts to convince even advanced users (who may not be deceived by previous methods) that their computer is infected. There are two variants of this method. Some rogue software creates a list of non-existent files and infections. Others select files from the computer at random, including valid clean system files. In a few rare instances, the "full" version of the rogue program actually attempts to remove these files, damaging the system.

These intentional false positives should be differentiated from an accidental false positive, which can occur in a scan by real legitimate security software.

Invited real discoveries

A variant on the false positive method is that some programs first download real malware to a computer and then "detect" them. This method is more rare as many of these malicious programs are detected by other legitimate anti-malware programs, limiting the effectiveness of the sell.

False security alerts

Many rogue applications now couple false positives with realistic and dramatic looking system security alerts. They may change the desktop background to a dramatic warning, continuously or sporadically redirect web browsers to a page that informs the user that they are infected and need to purchase a program. They may also change the homepage to a security warning, or bombard the user with continuous security alerts from the task bar, often using the yellow triangle with an exclamation point used by Windows to denote a system error. Some even go to the point of changing the screensaver to the BSOD, to make the user think that windows has crashed due to malware.

Locking various aspects of the system

To prevent removal by the user and entice the user to buy the program, rogue software will often lock various aspects of the system, including the control panel, the Add/Remove Programs feature, the ability to change the desktop, the ability to change the home page, and the ability to go to certain malware removal sites. These are all intended to prevent the user from removing the program and instead try to force them to buy the "full" version.

Detection and removal

Almost all reputable anti-spyware software will detect rogue software if it is installed on the scanned computer. Often, non-reputable rogue anti-spyware software will install a trojan horse to download the software from the maker's website, like Titan Shield.[2] Reputable anti-virus and anti-spyware software can detect the trojan even before the software is installed. Programs such as Ad-Aware SE, AVG Anti-Virus, Avast!, etc, can usually detect these with their real-time protection modules. HIPS software such as the Defense+ module of Comodo Internet Security is also capable of detecting and stopping the methods rogue software use to install onto a computer. However, often removal of new, aggressive rogue programs requires the use of programs such as HijackThis combined with manual removal processes because it can take quite a while before the manufacturers of the above mentioned legitimate programs learn how to automate the process and update their programs. In addition, rogue software sometimes has hidden parts that rebuild the rogue if they are partially removed. Other options for removal include use of a bootable "rescue disk" or reformatting the hard disk and reinstalling the operating system (the only way to ensure that the computer is 100% clean). If the rogue doesn't limit the user, then it is possible to manually remove the software.

Lawsuits

Recently, lawmakers as well as private and public citizens have attempted to shut down vendors of these companies. XPdefender, WinSpywareProtect, WinDefender, WinFixer, MalwareCore, and Antivirus 2009 have been named in lawsuits. Notably due to the vendors of those programs creating extremely similar names, slogans & user-interfaces, all in an effort to confuse users about names of legitimate security programs, EXAMPLE: Norton Internet Security and Windows Defender confused with MS Antivirus.

Partial list of rogue software

There are a large number of fake anti-spyware programs active on the Internet. Typically, widely-distributed Web banner ads falsely warn users that their computers have been infected with malware, enticing them to download the rogue software. Once installed, the software uses human engineering and false positives to manipulate the user into purchasing the software. These programs do not actually remove spyware — or worse, may add more.

The following is a partial list of known rogue software. Often the same software is distributed under several names. Many currently do not have Wikipedia articles.

See also

References

[84]

  1. ^ Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites
  2. ^ TitanShield - Symantec.com
  3. ^ Precise Security - Advanced Cleaner
  4. ^ Spyware Warrior - AlfaCleaner
  5. ^ BleepingComputer - AntiSpyCheck 2.1
  6. ^ BleepingComputer - AntispyStorm
  7. ^ 2-Spyare - AntiSpywareExpert
  8. ^ 2-Spyware - AntiSpywareMaster
  9. ^ Precise Security - AntiSpywareSuite
  10. ^ BleepingComputer - AntiSpyware Shield
  11. ^ BleepingComputer - Antivermins
  12. ^ BleepingComputer - Antivirgear
  13. ^ BleepingComputer - Antivirus 2008
  14. ^ 2-Spyware - Antivirus 2009
  15. ^ Article noting that Antivirus 2010 and Anti-virus-1 are the same
  16. ^ Details on Antivirus 2010 showing it is rogue, its symptoms and removal
  17. ^ BleepingComputer - Antivirus360
  18. ^ BleepingComputer - AntivirusPro2009
  19. ^ Symantec - AntiVirus Gold
  20. ^ BleepingComputer - Antivirus Master
  21. ^ Symantec - Antivirus XP
  22. ^ 2-Spyware - Avatod Antispyware
  23. ^ SpywareRemove - Awola
  24. ^ BleepingComputer - Brave Sentry
  25. ^ SpywareRemove - BestsellerAntivirus
  26. ^ 2-Spyware - Cleanator
  27. ^ McAfee - ContraVirus
  28. ^ XP-Vista - Doctor Antivirus
  29. ^ 2-Spyare - Doctor Antivirus 2008
  30. ^ Symantec Symantec - DriveCleaner
  31. ^ MalwareBytes - EasySpywareCleaner
  32. ^ Symantec - Errorsafe
  33. ^ 411-Spyare - GreenAV2009
  34. ^ 2-Spyare - IE Antivirus
  35. ^ MalwareBytes - IEDefender
  36. ^ SpywareRemove - InfeStop
  37. ^ Symantec - Internet Antivirus
  38. ^ 2-Spyare - KVMSecure
  39. ^ Symantec - MacSweeper
  40. ^ MalwareBytes - MalwareCrush
  41. ^ MalwareBytes - MalwareCore
  42. ^ MalwareBytes - Malware Alarm
  43. ^ 2-Spyware - Malware Bell
  44. ^ 2-Spyware - Malware Defender
  45. ^ BleepingComputer - MS Antivirus
  46. ^ http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009]
  47. ^ 2-Spyware - MaxAntispy
  48. ^ Sunbelt Security - Netcom3 Cleaner
  49. ^ 411-spyware - PCSecureSystem
  50. ^ BleepingComputer - PC Antispy
  51. ^ MalwareBytes - PC Clean Pro
  52. ^ SpywareRemove - PC Privacy Cleaner
  53. ^ BleepingComputer - PestTrap
  54. ^ MalwareBytes - PerfectCleaner
  55. ^ BleepingComputer - Perfect Defender 2009
  56. ^ BleepingComputer - PersonalAntiSpy Free
  57. ^ http://www.spywarewarrior.com/rogue_anti-spyware.htm SpywareWarrior - PAL Spyware Remover]
  58. ^ ComputerAssociates - PCPrivacy Tools
  59. ^ SpywareRemove - PC Antispyware
  60. ^ SpywareRemove - PSGuard
  61. ^ BleepingComputer - Rapid AntiVirus
  62. ^ BleepingComputer - Real Antivirus
  63. ^ Precise Security - Registry Great
  64. ^ Emsi Soft - SaliarAR
  65. ^ SpywareRemove - SecurePCCleaner
  66. ^ Precise Security - Security Toolbar 7.1
  67. ^ 2-Spyware - Smart Antivirus 2009
  68. ^ Symantec
  69. ^ Spyware Warrior - Spy Away
  70. ^ BleepingComputer - SpyCrush
  71. ^ Symantec - SpyDawn
  72. ^ Precise Security - SpyGuarder
  73. ^ BleepingComputer - SpyHeal
  74. ^ 411-Spyware - SpyMarshal
  75. ^ Symantec - Spylocked
  76. ^ Symantec - SpySheriff
  77. ^ Symantec - SpySpotter
  78. ^ 2-Spyare - SpywareBot
  79. ^ Symantec - Spyware Quake
  80. ^ MalwareBytes - Spyware Striker Pro]
  81. ^ Symantec
  82. ^ Symantec
  83. ^ [1]
  84. ^ http://www.pcthreat.com/parasitebyid-7817en.html | Information about WinPC Defendfer