<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Geek and More &#187; Fake Anti-Virus</title>
	<atom:link href="http://www.techgeekandmore.com/tag/fake-anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techgeekandmore.com</link>
	<description>Technology Explained for All</description>
	<lastBuildDate>Mon, 06 Sep 2010 04:44:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Alert: Another Fake Email install Rogue Software (From Panda Labs Blog)</title>
		<link>http://www.techgeekandmore.com/2010/03/06/antivirus2010-fake-email-do-not-click-on-attachment-alert-pandalabs/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=antivirus2010-fake-email-do-not-click-on-attachment-alert-pandalabs</link>
		<comments>http://www.techgeekandmore.com/2010/03/06/antivirus2010-fake-email-do-not-click-on-attachment-alert-pandalabs/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 05:10:00 +0000</pubDate>
		<dc:creator>anovelo</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[#Panda Labs Alert]]></category>
		<category><![CDATA[Antispyware 2010]]></category>
		<category><![CDATA[Antivirus2010]]></category>
		<category><![CDATA[defender 2010]]></category>
		<category><![CDATA[Fake Anti-Virus]]></category>
		<category><![CDATA[Fake email malware]]></category>
		<category><![CDATA[Rogue Antivirus Malware]]></category>
		<category><![CDATA[Rogue Malware Alert]]></category>

		<guid isPermaLink="false">http://www.techgeekandmore.com/2010/03/06/antivirus2010-fake-email-do-not-click-on-attachment-alert-pandalabs/</guid>
		<description><![CDATA[One of the biggest reasons why TechGeekandMore started came from how many customers I had (and still have) to visit every week to either clean Viruses of PC or (even worse) recover as many files as possible and then reinstall Windows.  I wanted a way a to try and alert and educate my customers about how …..The message seems to have been sent by a member of your family through a legal website to download and send postcards, so that users don’t suspect. In order to view the postcard, you have to open the attached file. It’s a file compressed with zip and if you run it, a rogueware program will be installed in your computer, which is different depending on the message and the operating system you have.]]></description>
			<content:encoded><![CDATA[<p>     One of the biggest reasons why TechGeekandMore started came from how many customers I had (and still have) to visit every week to either clean Viruses of PC or (even worse) recover as many files as possible and then reinstall Windows.  I wanted a way a to try and alert and educate my customers about how …..</p>
<p>- No African Prince was going give you millions</p>
<p>- Emails that say that they are from a friend or family with that weird looking attachment could actually be fake</p>
<p>- Hot College Girl……well this one just really doesn’t have much beyond “Don&#8217;t do it”.</p>
<p>ETC ETC ETC…….</p>
<p>     In those lines a new email starting this week, that has only 1 goal, to trick you into downloading and installing some really nasty software (more of the fake antivirus software).  This new email says that “You have received a postcard”……</p>
<p>The following information comes from PANDALABS blog ( <a href="http://pandalabs.pandasecurity.com/the-thousand-faced-rogue/" title="http://pandalabs.pandasecurity.com/the-thousand-faced-rogue/"   >http://pandalabs.pandasecurity.com/the-thousand-faced-rogue/</a>)</p>
<p>******************************************************************************************************************</p>
<h3>The Thousand-Faced Rogue</h3>
<p>Mar 5</p>
<ul>
<li>Posted on 03/5/10 by <cite><a href="http://pandalabs.pandasecurity.com/author/olaiz/"   >Olaiz</a></cite></li>
</ul>
<p>We want to inform you of a new flood of email messages that seem to contain a postcard but are actually distributing malware. Concretely, we’ve seen several thousands in a few hours.</p>
<p>It’s not the first time we see emails like this in circulation, as subjects like “You’ve received a postcard” are very recurrent.</p>
<p>The message is like the following:</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/03/postcardzip_en.jpg" alt="postcardzip_en" width="541" height="332" /></p>
<p>The message seems to have been sent by a member of your family through a legal website to download and send postcards, so that users don’t suspect. In order to view the postcard, you have to open the attached file. It’s a file compressed with zip and if you run it, a rogueware program will be installed in your computer, which is different depending on the message and the operating system you have.</p>
<p>The following are some of the names of the fake antivirus that can be installed in your computer if you run this file:</p>
<p>% Antispyware 2010</p>
<p>Antivirus % 2010</p>
<p>% Guardian 2010</p>
<p>% Guardian</p>
<p>% Defender 2010</p>
<p>% Antivirus</p>
<p>% Antivirus 2010</p>
<p>% Antivirus Pro</p>
<p>% Antivirus Pro 2010</p>
<p>% Internet Security</p>
<p>% Internet Security 2010</p>
<p>where % stands for the operating system of the computer in which it is going to be installed. Some examples: XPAntispyware2010, Vista Guardian, Win 7 Antivirus Pro.</p>
<p>Let’s take as an example Antivirus XP 2010 and see the actions it carries out once it has been installed in the computer.</p>
<p>As every rogueware, it starts scanning the system to check if the computer is infected.</p>
<p>Once finished, it displays a list with the malware that has detected in your computer to make you believe that you’ve got a problem and that this program will offer you the solution:</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/03/AntivirusXP2010.jpg" alt="AntivirusXP2010" width="550" height="387" /></p>
<p>However, all the malware it has detected makes reference to unexisting files, so the only threat you have is the own rogue.</p>
<p>Additionally, it prevents the execution of programs whose window title makes reference to the following programs:</p>
<p>Internet Explorer</p>
<p>Firefox</p>
<p>Several security suites.</p>
<p>When you try to run any of these, a message is displayed informing you that these programs are infected and recommending you to install the fake antivirus to solve the problem.</p>
<p>The following image belongs to the message that is displayed when Firefox is run:</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/03/Firefox_infected.jpg" alt="Firefox_infected" width="481" height="414" /></p>
<p>It also contains code to uninstall different security solutions. This way, the computer would be unprotected and the real antivirus programs could not detect it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techgeekandmore.com/2010/03/06/antivirus2010-fake-email-do-not-click-on-attachment-alert-pandalabs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ALERT: Fake Antivirus software really adware meant to take your money $$$</title>
		<link>http://www.techgeekandmore.com/2009/03/02/warning-fake-antivirus-software-really-adware-meant-to-take-your-money/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=warning-fake-antivirus-software-really-adware-meant-to-take-your-money</link>
		<comments>http://www.techgeekandmore.com/2009/03/02/warning-fake-antivirus-software-really-adware-meant-to-take-your-money/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 01:38:00 +0000</pubDate>
		<dc:creator>anovelo</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[ALERT from Panda Labs]]></category>
		<category><![CDATA[Fake Anti-Virus]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Panda Labs]]></category>
		<category><![CDATA[rogueware]]></category>
		<category><![CDATA[scareware fake antivirus]]></category>

		<guid isPermaLink="false">http://www.rj-diamond.com/alex/2009/03/02/warning-fake-antivirus-software-really-adware-meant-to-take-your-money/</guid>
		<description><![CDATA[Anti-Virus-1 is adware, specifically a "fake antivirus". As with all such adware, it is designed to simulate a scan of the computer, supposedly detecting thousands of strains of (non-existent) malware. The end aim is to sell users a pay version of the fake antivirus in order to eliminate the threats.]]></description>
			<content:encoded><![CDATA[<h3><a href="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/pandalabs_security.jpg"   ><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="pandalabs_security" border="0" alt="pandalabs_security" src="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/pandalabs_security_thumb.jpg" width="76" height="60" /></a> <font size="2">Story (and pictures) from the Panda Labs website (<strong>LINK:</strong> </font><a href="http://www.pandasecurity.com/emailhtml/oxygen/022809_ENG_in.htm" title="http://www.pandasecurity.com/emailhtml/oxygen/022809_ENG_in.htm"   ><font size="2">http://www.pandasecurity.com/emailhtml/oxygen/022809_ENG_in.htm</font></a><font size="2">)</font></h3>
<p><strong>Anti-Virus-1: A new fake antivirus</strong></p>
<p>Anti-Virus-1 is adware, specifically a &quot;fake antivirus&quot;. As with all such adware, it is designed to simulate a scan of the computer, supposedly detecting thousands of strains of (non-existent) malware. The end aim is to sell users a pay version of the fake antivirus in order to eliminate the threats.</p>
<p>When run, this adware warns the user that the computer is not protected. The main <a href="http://www.flickr.com/photos/panda_security/3313653378/"   >screen displayed</a> is a spoof of the Window Security Center</p>
<p><a href="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653378_e9307e88f8.jpg"   ><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="3313653378_e9307e88f8" border="0" alt="3313653378_e9307e88f8" src="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653378_e9307e88f8_thumb.jpg" width="491" height="377" /></a> </p>
<p>It then pretends to <a href="http://www.flickr.com/photos/panda_security/3313653384/"   >scan the system for malware</a>. If users do not immediately take the bait and buy the pay version of the fake antivirus, the malicious code will sporadically <a href="http://www.flickr.com/photos/panda_security/3313653386/"   >display a message reminding the user that the computer is infected</a></p>
<p><a href="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653386_d7d2477df1.jpg"   ><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="3313653386_d7d2477df1" border="0" alt="3313653386_d7d2477df1" src="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653386_d7d2477df1_thumb.jpg" width="482" height="387" /></a> </p>
<p>In warning messages, and after the fake scan, a link is provided from which users can download the fake antivirus. Anyone clicking on the link will be redirected to a page like <a href="http://www.flickr.com/photos/panda_security/3313653390/"   >this </a>.</p>
<p><a href="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653390_a9554b8264.jpg"   ><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="3313653390_a9554b8264" border="0" alt="3313653390_a9554b8264" src="http://www.rj-diamond.com/alex/wp-content/uploads/2010/01/3313653390_a9554b8264_thumb.jpg" width="487" height="380" /></a> </p>
<p>Additionally, when infected users visit certain Web pages with comparative reviews of antivirus products, there will be redirected to a spoof page showing a review of an &#8216;antivirus&#8217;, called Antivirus2010, with functions and characteristics similar to Anti-Virus-1.</p>
<p>&quot;By doing this, cyber-crooks hope that users will download this adware on their own initiative. This makes it far less likely that users will suspect that they have been infected and consequently more likely that they will buy the fake antivirus&quot;, explains Luis Corrons, Technical Director of Panda Labs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techgeekandmore.com/2009/03/02/warning-fake-antivirus-software-really-adware-meant-to-take-your-money/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
