Rogue security software: Difference between revisions
PedroDaGr8 (talk | contribs) →Partial list of rogue software: Added refs for MalwareBell - Perfect Defender 2009 |
PedroDaGr8 (talk | contribs) →Partial list of rogue software: Added refs for PersonalAntispy Free - SpywareBot - Removed plus4scan and others as they are sites not programs |
||
Line 39: | Line 39: | ||
{{Col-break}} |
{{Col-break}} |
||
* [[Advanced Cleaner]]<ref>[http://www.precisesecurity.com/blogs/2007/08/09/advanced-cleaner/ Precise Security - Advanced Cleaner]</ref> |
* [[Advanced Cleaner]]<ref>[http://www.precisesecurity.com/blogs/2007/08/09/advanced-cleaner/ Precise Security - Advanced Cleaner]</ref> |
||
* [[AlfaCleaner]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm |
* [[AlfaCleaner]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm Spyware Warrior - AlfaCleaner]</ref> |
||
* [[AntiSpyCheck 2.1]]<ref>[http://www.bleepingcomputer.com/uninstall/10802/AntiSpyCheck-2.1.0.html BleepingComputer - AntiSpyCheck 2.1]</ref> |
* [[AntiSpyCheck 2.1]]<ref>[http://www.bleepingcomputer.com/uninstall/10802/AntiSpyCheck-2.1.0.html BleepingComputer - AntiSpyCheck 2.1]</ref> |
||
* [[AntiSpyStorm]]<ref>[http://www.bleepingcomputer.com/uninstall/5779/AntispyStorm-1.01.0027.html BleepingComputer - AntispyStorm]</ref> |
* [[AntiSpyStorm]]<ref>[http://www.bleepingcomputer.com/uninstall/5779/AntispyStorm-1.01.0027.html BleepingComputer - AntispyStorm]</ref> |
||
* [[AntiSpywareExpert]]<ref>[http:// |
* [[AntiSpywareExpert]]<ref>[http://www.2-spyware.com/remove-antispywareexpert.html 2-Spyare - AntiSpywareExpert]</ref> |
||
* [[AntiSpywareMaster]]<ref>[http://www.2-spyware.com/remove-antispywaremaster.html 2-Spyware - AntiSpywareMaster]</ref> |
* [[AntiSpywareMaster]]<ref>[http://www.2-spyware.com/remove-antispywaremaster.html 2-Spyware - AntiSpywareMaster]</ref> |
||
* [[AntiSpywareSuite]]<ref>[http://www.precisesecurity.com/blogs/2008/07/03/spyshredder-professional-antispyware-suite/ Precise Security - AntiSpywareSuite]</ref> |
* [[AntiSpywareSuite]]<ref>[http://www.precisesecurity.com/blogs/2008/07/03/spyshredder-professional-antispyware-suite/ Precise Security - AntiSpywareSuite]</ref> |
||
Line 53: | Line 53: | ||
* [[MS Antivirus|Antivirus 360]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-360 BleepingComputer - Antivirus360]</ref> |
* [[MS Antivirus|Antivirus 360]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-360 BleepingComputer - Antivirus360]</ref> |
||
* [[MS Antivirus|Antivirus Pro 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-pro-2009 BleepingComputer - AntivirusPro2009]</ref> |
* [[MS Antivirus|Antivirus Pro 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-antivirus-pro-2009 BleepingComputer - AntivirusPro2009]</ref> |
||
* [[AntiVirus Gold]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-032415-1558-99 Symantec]</ref> |
* [[AntiVirus Gold]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-032415-1558-99 Symantec - AntiVirus Gold]</ref> |
||
* [[MS Antivirus|Antivirus Master]]<ref>[http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-master BleepingComputer - Antivirus Master]</ref> |
* [[MS Antivirus|Antivirus Master]]<ref>[http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-master BleepingComputer - Antivirus Master]</ref> |
||
* [[MS Antivirus|Antivirus XP 2008]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2 Symantec]</ref> |
* [[MS Antivirus|Antivirus XP 2008]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2 Symantec - Antivirus XP]</ref> |
||
* [[Avatod Antispyware 8.0]] <ref>[http://www.2-spyware.com/remove-avatod-antispyware.html 2-Spyware - Avatod Antispyware]</ref> |
* [[Avatod Antispyware 8.0]] <ref>[http://www.2-spyware.com/remove-avatod-antispyware.html 2-Spyware - Avatod Antispyware]</ref> |
||
* [[Awola]]<ref>[http://www.spywareremove.com/removeAwola.html SpywareRemove - Awola]</ref> |
* [[Awola]]<ref>[http://www.spywareremove.com/removeAwola.html SpywareRemove - Awola]</ref> |
||
Line 81: | Line 81: | ||
* [[Malware Defender]] (not to be confused with the HIPS firewall of the same name)<ref>[http://www.2-spyware.com/remove-malware-defender-2009.html 2-Spyware - Malware Defender]</ref> |
* [[Malware Defender]] (not to be confused with the HIPS firewall of the same name)<ref>[http://www.2-spyware.com/remove-malware-defender-2009.html 2-Spyware - Malware Defender]</ref> |
||
* [[MS Antivirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-ms-antivirus BleepingComputer - MS Antivirus]</ref> |
* [[MS Antivirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-ms-antivirus BleepingComputer - MS Antivirus]</ref> |
||
* [[MS AntiSpyware 2009]]<ref>http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009</ref> |
* [[MS AntiSpyware 2009]]<ref>http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009]</ref> |
||
* [[MaxAntiSpy]]<ref>[http://www.2-spyware.com/remove-maxantispy.html 2-Spyware - MaxAntispy]</ref> |
* [[MaxAntiSpy]]<ref>[http://www.2-spyware.com/remove-maxantispy.html 2-Spyware - MaxAntispy]</ref> |
||
* [[Netcom3 Cleaner]]<ref>[http://www.sunbeltsecurity.com/ThreatDisplay.aspx?name=Netcom3%20Cleaner&tid=417577&cs=53B10F8781B13BE938E57A2E7FBD042A Sunbelt Security - Netcom3 Cleaner]</ref> |
* [[Netcom3 Cleaner]]<ref>[http://www.sunbeltsecurity.com/ThreatDisplay.aspx?name=Netcom3%20Cleaner&tid=417577&cs=53B10F8781B13BE938E57A2E7FBD042A Sunbelt Security - Netcom3 Cleaner]</ref> |
||
Line 88: | Line 88: | ||
* [[PC Clean Pro]] <ref>[http://www.malwarebytes.org/forums/index.php?showtopic=5252 MalwareBytes - PC Clean Pro]</ref> |
* [[PC Clean Pro]] <ref>[http://www.malwarebytes.org/forums/index.php?showtopic=5252 MalwareBytes - PC Clean Pro]</ref> |
||
* [[PC Privacy Cleaner]]<ref>[http://www.spywareremove.com/removePCPrivacyCleaner.html SpywareRemove - PC Privacy Cleaner]</ref> |
* [[PC Privacy Cleaner]]<ref>[http://www.spywareremove.com/removePCPrivacyCleaner.html SpywareRemove - PC Privacy Cleaner]</ref> |
||
* [[PC SpeedScan Pro]] (distributed by [[FinallyFast.com]] |
* [[PC SpeedScan Pro]] (distributed by [[FinallyFast.com]], Rogueness is questionable) |
||
* [[PestTrap]] <ref>[http://www.bleepingcomputer.com/forums/topic58391.html BleepingComputer - PestTrap]</ref> |
* [[PestTrap]] <ref>[http://www.bleepingcomputer.com/forums/topic58391.html BleepingComputer - PestTrap]</ref> |
||
* [[PerfectCleaner]]<ref>[http://www.malwarebytes.org/roguenet.php?id=266 MalwareBytes - PerfectCleaner]</ref> |
* [[PerfectCleaner]]<ref>[http://www.malwarebytes.org/roguenet.php?id=266 MalwareBytes - PerfectCleaner]</ref> |
||
* [[Perfect Defender 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-perfect-defender-2009 BleepingComputer - Perfect Defender 2009]</ref> |
* [[Perfect Defender 2009]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-perfect-defender-2009 BleepingComputer - Perfect Defender 2009]</ref> |
||
* [[PersonalAntiSpy Free]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-personalantispy BleepingComputer - PersonalAntiSpy Free]</ref> |
|||
* [[PersonalAntiSpy Free]] |
|||
* [[PAL Spyware Remover]]<ref>http://www.spywarewarrior.com/rogue_anti-spyware.htm SpywareWarrior - PAL Spyware Remover]</ref> |
|||
* [[PAL Spyware Remover]] |
|||
* [[PCPrivacy Tools]]<ref>[http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453116863 ComputerAssociates - PCPrivacy Tools]</ref> |
|||
* [[PCPrivacytool]] |
|||
* [[PC Antispyware]]<ref>[http://www.spywareremove.com/removePCAntispyware.html SpywareRemove - PC Antispyware]</ref> |
|||
* [[PC-Antispyware]] |
|||
* PSGuard<ref>[http://www.spywareremove.com/removePSGuard.html SpywareRemove - PSGuard]</ref> |
|||
* [[Plus4scan.com]] |
|||
* [[Rapid AntiVirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-rapidantivirus BleepingComputer - Rapid AntiVirus]</ref> |
|||
* [[Premium-Antivirus-Defence]] |
|||
* [[Real AntiVirus]]<ref>[http://www.bleepingcomputer.com/malware-removal/remove-real-antivirus BleepingComputer - Real Antivirus]</ref> |
|||
* PSGuard |
|||
* [[Registry Great]]<ref>[http://www.precisesecurity.com/threats/registry-great/ Precise Security - Registry Great]</ref> |
|||
* [[Rapid AntiVirus]] |
|||
* [[SaliarAR]]<ref>[http://www.emsisoft.com/en/malware/?Adware.Win32.SaliarAR Emsi Soft - SaliarAR]</ref> |
|||
* [[Real AntiVirus]] |
|||
* [[SecurePCCleaner]]<ref>[http://www.spywareremove.com/removeSecurePCCleaner.html SpywareRemove - SecurePCCleaner]</ref> |
|||
* [[Registry Great]] |
|||
* [[Security Toolbar 7.1]]<ref>[http://www.precisesecurity.com/blogs/2007/05/24/adware-security-toolbar-71/ Precise Security - Security Toolbar 7.1]</ref> |
|||
* [[SaliarAR]] |
|||
* [[Smart Antivirus 2009]]<ref>[http://www.2-spyware.com/remove-smart-antivirus-2009.html 2-Spyware - Smart Antivirus 2009]</ref> |
|||
* [[SecurePCCleaner]] |
|||
* [[Security toolbar 7.1]] |
|||
* [[Smart Antivirus 2008]] |
|||
* [[Smart Antivirus 2009]] |
|||
* [[SpyAxe]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-123015-4116-99 Symantec]</ref> |
* [[SpyAxe]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-123015-4116-99 Symantec]</ref> |
||
* [[Spy Away]]<ref>[http://www.spywarewarrior.com/rogue_anti-spyware.htm Spyware Warrior - Spy Away]</ref> |
|||
* [[Spy Away]] |
|||
* [[SpyCrush]]<ref>[http://www.bleepingcomputer.com/forums/topic80749.html BleepingComputer - SpyCrush]</ref> |
|||
* [[SpyCrush]] |
|||
* [[Spydawn]] |
* [[Spydawn]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053116-5727-99 Symantec - SpyDawn]</ref> |
||
* [[SpyGuarder]]<ref>[http://www.precisesecurity.com/threats/spyguarder/ Precise Security - SpyGuarder]</ref> |
|||
* [[SpyGuarder]] |
|||
* [[SpyHeal]] (a.k.a SpyHeals & VirusHeal)<ref>[http://www.bleepingcomputer.com/forums/topic58129.html BleepingComputer - SpyHeal]</ref> |
|||
* [[SpyHeal]] |
|||
* [[SpyMarshal]]<ref>[http://www.411-spyware.com/spymarshal 411-Spyware - SpyMarshal]</ref> |
|||
* [[SpyMarshal]] |
|||
* [[Spylocked]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053117-1026-99 Symantec]</ref> |
* [[Spylocked]] <ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2007-053117-1026-99 Symantec - Spylocked]</ref> |
||
* [[SpySheriff]] |
* [[SpySheriff]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2005-122910-4625-99 Symantec - SpySheriff]</ref> |
||
* [[SpySpotter]]<ref>[http://www.symantec.com/security_response/writeup.jsp?docid=2006-061611-4947-99 Symantec - SpySpotter]</ref> |
|||
* [[SpySpotter]] |
|||
* [[SpywareBot]] |
* [[SpywareBot]] ([[Spybot - Search & Destroy]] knockoff)<ref>[http://www.2-spyware.com/review-spywarebot.html 2-Spyare - SpywareBot]</ref> |
||
{{Col-break}} |
{{Col-break}} |
||
* [[Spyware Cleaner]] |
* [[Spyware Cleaner]] |
Revision as of 00:22, 18 April 2009
This article needs additional citations for verification. (January 2009) |
Rogue security software is software that uses malware (malicious software) or malicious tools to advertise or install itself or to force computer users to pay for removal of nonexistent malware. Rogue software will often install a trojan horse to download a trial version, or it will execute other unwanted actions. The first and most comprehensive study of rogue and real antispyware programs was carried out by Eric L. Howes.[1]
Installation
The main goal of rogue software makers is to install and sell their product. In order to attempt to install their program, fake Windows dialog boxes and other browser pop-ups are often displayed attempting to entice the user to click on them. Most of the time, they will display a message such as "WARNING! Your computer is infected with Spyware/Adware/Viruses! Buy [software name] to remove it!", a variant of which will say "Click OK to scan your system" instead of asking the user to outright buy the software. Another variant on this method involves telling the user their "Computer/Internet Connection/OS is not optimized and to Click Here to scan now". Usually, when the dialog box's OK button is clicked, this will direct the user to a malicious website, which will install the program. Sometimes, even clicking the upper right hand X button to close the dialog box will produce the same effect. (Pressing Alt+F4 or using Task Manager with Ctrl-Alt-Delete can circumvent that trick). Some software, like SpyAxe, will automatically download the trial version without any user action, in a process know as a drive-by installation. Along with the installation of the rogue programs, many sites now attempt to install multiple trojans at one time by downloading what is called a dropper first, which then loads a variety of malware to the computer.
Tactics
Once installed, the programs rely on several tactics to attempt to entice the user into purchasing a "full" version. These include false positives, downloaded malware, false security alerts and locking various aspects of the system to prevent user changes.
False positives
A common method used by rogue security software makers use is that of intentional false positives. A false positive is a fake or false malware detection in a computer scan. This attempts to convince even advanced users (who may not be deceived by previous methods) that their computer is infected. There are two variants of this method. Some rogue software creates a list of non-existent files and infections. Others select files from the computer at random, including valid clean system files. In a few rare instances, the "full" version of the rogue program actually attempts to remove these files, damaging the system.
These intentional false positives should be differentiated from an accidental false positive, which can occur in a scan by real legitimate security software.
Invited real discoveries
A variant on the false positive method is that some programs first download real malware to a computer and then "detect" them. This method is more rare as many of these malicious programs are detected by other legitimate anti-malware programs, limiting the effectiveness of the sell.
False security alerts
Many rogue applications now couple false positives with realistic and dramatic looking system security alerts. They may change the desktop background to a dramatic warning, continuously or sporadically redirect web browsers to a page that informs the user that they are infected and need to purchase a program. They may also change the homepage to a security warning, or bombard the user with continuous security alerts from the task bar, often using the yellow triangle with an exclamation point used by Windows to denote a system error. Some even go to the point of changing the screensaver to the BSOD, to make the user think that windows has crashed due to malware.
Locking various aspects of the system
To prevent removal by the user and entice the user to buy the program, rogue software will often lock various aspects of the system, including the control panel, the Add/Remove Programs feature, the ability to change the desktop, the ability to change the home page, and the ability to go to certain malware removal sites. These are all intended to prevent the user from removing the program and instead try to force them to buy the "full" version.
Detection and removal
Almost all reputable anti-spyware software will detect rogue software if it is installed on the scanned computer. Often, non-reputable rogue anti-spyware software will install a trojan horse to download the software from the maker's website, like Titan Shield.[2] Reputable anti-virus and anti-spyware software can detect the trojan even before the software is installed. Programs such as Ad-Aware SE, AVG Anti-Virus, Avast!, etc, can usually detect these with their real-time protection modules. HIPS software such as the Defense+ module of Comodo Internet Security is also capable of detecting and stopping the methods rogue software use to install onto a computer. However, often removal of new, aggressive rogue programs requires the use of programs such as HijackThis combined with manual removal processes because it can take quite a while before the manufacturers of the above mentioned legitimate programs learn how to automate the process and update their programs. In addition, rogue software sometimes has hidden parts that rebuild the rogue if they are partially removed. Other options for removal include use of a bootable "rescue disk" or reformatting the hard disk and reinstalling the operating system (the only way to ensure that the computer is 100% clean). If the rogue doesn't limit the user, then it is possible to manually remove the software.
Lawsuits
Recently, lawmakers as well as private and public citizens have attempted to shut down vendors of these companies. XPdefender, WinSpywareProtect, WinDefender, WinFixer, MalwareCore, and Antivirus 2009 have been named in lawsuits. Notably due to the vendors of those programs creating extremely similar names, slogans & user-interfaces, all in an effort to confuse users about names of legitimate security programs, EXAMPLE: Norton Internet Security and Windows Defender confused with MS Antivirus.
Partial list of rogue software
There are a large number of fake anti-spyware programs active on the Internet. Typically, widely-distributed Web banner ads falsely warn users that their computers have been infected with malware, enticing them to download the rogue software. Once installed, the software uses human engineering and false positives to manipulate the user into purchasing the software. These programs do not actually remove spyware — or worse, may add more.
The following is a partial list of known rogue software. Often the same software is distributed under several names. Many currently do not have Wikipedia articles.
See also
References
- ^ Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites
- ^ TitanShield - Symantec.com
- ^ Precise Security - Advanced Cleaner
- ^ Spyware Warrior - AlfaCleaner
- ^ BleepingComputer - AntiSpyCheck 2.1
- ^ BleepingComputer - AntispyStorm
- ^ 2-Spyare - AntiSpywareExpert
- ^ 2-Spyware - AntiSpywareMaster
- ^ Precise Security - AntiSpywareSuite
- ^ BleepingComputer - AntiSpyware Shield
- ^ BleepingComputer - Antivermins
- ^ BleepingComputer - Antivirgear
- ^ BleepingComputer - Antivirus 2008
- ^ 2-Spyware - Antivirus 2009
- ^ Article noting that Antivirus 2010 and Anti-virus-1 are the same
- ^ Details on Antivirus 2010 showing it is rogue, its symptoms and removal
- ^ BleepingComputer - Antivirus360
- ^ BleepingComputer - AntivirusPro2009
- ^ Symantec - AntiVirus Gold
- ^ BleepingComputer - Antivirus Master
- ^ Symantec - Antivirus XP
- ^ 2-Spyware - Avatod Antispyware
- ^ SpywareRemove - Awola
- ^ BleepingComputer - Brave Sentry
- ^ SpywareRemove - BestsellerAntivirus
- ^ 2-Spyware - Cleanator
- ^ McAfee - ContraVirus
- ^ XP-Vista - Doctor Antivirus
- ^ 2-Spyare - Doctor Antivirus 2008
- ^ Symantec Symantec - DriveCleaner
- ^ MalwareBytes - EasySpywareCleaner
- ^ Symantec - Errorsafe
- ^ 411-Spyare - GreenAV2009
- ^ 2-Spyare - IE Antivirus
- ^ MalwareBytes - IEDefender
- ^ SpywareRemove - InfeStop
- ^ Symantec - Internet Antivirus
- ^ 2-Spyare - KVMSecure
- ^ Symantec - MacSweeper
- ^ MalwareBytes - MalwareCrush
- ^ MalwareBytes - MalwareCore
- ^ MalwareBytes - Malware Alarm
- ^ 2-Spyware - Malware Bell
- ^ 2-Spyware - Malware Defender
- ^ BleepingComputer - MS Antivirus
- ^ http://www.bleepingcomputer.com/malware-removal/remove-ms-antispyware-2009 BleepingComputer MS Antispyware 2009]
- ^ 2-Spyware - MaxAntispy
- ^ Sunbelt Security - Netcom3 Cleaner
- ^ 411-spyware - PCSecureSystem
- ^ BleepingComputer - PC Antispy
- ^ MalwareBytes - PC Clean Pro
- ^ SpywareRemove - PC Privacy Cleaner
- ^ BleepingComputer - PestTrap
- ^ MalwareBytes - PerfectCleaner
- ^ BleepingComputer - Perfect Defender 2009
- ^ BleepingComputer - PersonalAntiSpy Free
- ^ http://www.spywarewarrior.com/rogue_anti-spyware.htm SpywareWarrior - PAL Spyware Remover]
- ^ ComputerAssociates - PCPrivacy Tools
- ^ SpywareRemove - PC Antispyware
- ^ SpywareRemove - PSGuard
- ^ BleepingComputer - Rapid AntiVirus
- ^ BleepingComputer - Real Antivirus
- ^ Precise Security - Registry Great
- ^ Emsi Soft - SaliarAR
- ^ SpywareRemove - SecurePCCleaner
- ^ Precise Security - Security Toolbar 7.1
- ^ 2-Spyware - Smart Antivirus 2009
- ^ Symantec
- ^ Spyware Warrior - Spy Away
- ^ BleepingComputer - SpyCrush
- ^ Symantec - SpyDawn
- ^ Precise Security - SpyGuarder
- ^ BleepingComputer - SpyHeal
- ^ 411-Spyware - SpyMarshal
- ^ Symantec - Spylocked
- ^ Symantec - SpySheriff
- ^ Symantec - SpySpotter
- ^ 2-Spyare - SpywareBot
- ^ Symantec - Spyware Quake
- ^ MalwareBytes - Spyware Striker Pro]
- ^ Symantec
- ^ Symantec
- ^ [1]
- ^ http://www.pcthreat.com/parasitebyid-7817en.html | Information about WinPC Defendfer