Frequently Asked Questions

Sample of Infections

 

VirusProtect 3.9

 
A new version of VirusProtect rogue has been released:
This rogues looks like: VirusRay, Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.

 

VirusProtect 3.8

 
A new Rogue has been released: VirusProtect.
This rogues looks like: VirusRay, Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.

IE Defender

 
Rogue IE Defender coming with the fake codec multimedia decoder has been incuded to SmitfraudFix.



The authors of IE Defender are claiming on CastleCops forum that their software is "clean and is real antispyware".
Talking about the problem of the trojan fake codec that advertise for IE Defender installation, they post:

 
we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us.

Looking at the servers IP of IE Defender and the Trojan: they are the same. No more to say.

 

VirusRay 3.8

 
A new Rogue has been released: VirusRay.
This rogues looks like: VirusRay, Antivir Gear, VirusProtectPro , SpyDown, SpywareQuake.

 

Trojan SPM/LX

Smitfraud family Malware.
Displays fake alert messages, Hijacks desktop background.




 

 

Spyware.WinAntiVirus

 
A new version of Spyware.WinAntiVirus has been released.

 
 

AntiVirGear 3.8

 
A new version of the Rogue AntiVirGear has been released.
This rogues looks like: VirusProtectPro , SpyDown, SpywareQuake.

 
 

AntiVirGear 3.7

 
After the release of different version of VirusProtectPro (3.3 to 3.6) the rogue mutates to AntiVirGear 3.7. A modified version of SpyDown, SpywareQuake.

 
 

 

Privacy Danger Desktop Hijack

 
Privacy Danger is a componant of NewMediaCodec/VideoAccessCodec (VideoCach), a fake codec that displays alerts, Rogue popups, installs a BHO...

Desktop background modified:

 
 

SpyLocked

 
SpyLocked rogue, a modified version of SpyDown, SpyCrush, SpywareQuake.

 
 

SpyDown

 
SpyDown rogue, a modified version of SpyCrush, SpywareQuake (a lot of registry keys are the same).

 
 

SpyCrush

 
SpyCrush rogue, a modified version of SpywareQuake (a lot of registry keys are the same) and of VirusBurst(er), thanks to Security Cadets.

 

SpyMarshal

 
SpyMarshal rogue:

 
 

PestCapture

 
PestCapture rogue:
 

SpywareKnight

 
SpywareKnight rogue.

 

SpySoldier

 
SpySoldier rogue.
 

Registry Cleaner

 
Registry Cleaner rogue installs itself with fake warning messages displayed by a Trojan Downloader.





 

MalwareWiped

 
MalwareWiped rogue, a new version of MalwareWiper (MalwareWipe) rogue.

 

AntiVermins

 
AntiVermins rogue:

 
 

 

 

Windows XP Visual Quick Tips
or go to Amazon and do a search for this book