Fake Anti-Virus's [How to know when you have one] - Atmosphere - 04-18-2010
###How to know when you have a Fake AV and how to remove it###
Hello, I've had a lot of Fake Anti-Virus's get on my computer some how. I'm going to show some Fake Anti-Virus's that are new and how to get rid of them. Also, when I hear of new Fake Anti-Virus's I'll update my thread.
You might have symptoms like:
When the Fake Anti-Virus process is running it will close almost any running program while falsely stating that they are infected.
It also can block websites so you can follow a guide on how to remove the program.
You might go to www.google.com and it will say "Internet Explorer Warning - visiting this web site may harm your computer!"
or
When you open a trusted program like MSN it will say "This program is infected close now!".
Also, don't download anything or follow ANY GUIDE FROM spywareremove
Reputation is terrible.
BleepingComputer.com is trusted.
Anti-Virus Soft: This program also uses aggressive techniques to protect itself from being removed by anti-malware programs. When the Antivirus Soft process is running it will close almost any running program while falsely stating that they are infected. Antivirus Soft will also change the Proxy settings in Internet Explorer so that you cannot browse to any web site other than the site for Antivirus Soft so that you can purchase the program. It does this so that you cannot browse the web to find removal guides or download software that will help you remove the infection. Using these two methods, the program essentially ransoms the normal use of your computer until you purchase the program or use the guide below to remove the infection.
Removal Guide.
Antivirus7: When Antivirus7 is installed it will be set to start automatically when you login to Windows. Once started it will scan your computer and state that there are a variety of infections on your computer, but will not remove them until you first purchase the program. These infections are all fake, though, and the files it states are infected are actually legitimate Windows programs. Therefore please do not manually delete any of the files it states are infections as it may cause your Windows operating system to not operate properly.
Removal Guide.
Antivirus Suite: When Antivirus Suite starts it will perform various functions in order to protect itself from being removed. First, it will configure your Internet Explorer and Windows Internet settings to use a proxy server. This proxy server will not allow you to update anti-malware programs or let you visit a variety of sites and will instead show a screen stating that the site you are visiting is harmful. This warning will state "Internet Explorer Warning - visiting this web site may harm your computer!" and then prompt you to purchase Antivirus Suite in order to protect yourself. The program will also not allow you to launch most applications other than those absolutely required for Windows or Antivirus Suite to run properly. When you attempt to launch other programs, Antivirus Suite will state that they are infected. It will then prompt you to purchase the rogue to repair the infection. These are just further scare tactics and should be ignored.
Removal Guide.
--------------------------------------------------------------------------
There are many more of these kind of Fake Anti-Virus's
If you get Fake Anti-virus like these I would recommend downloading Malwarebytes and SUPERAntiSpyware plus ESET online scanner.
If that doesn't seem to do the job please go to the White Hat Help section or follow a Guide from BleepingComputer.com.
Hope this helps you stay clear of these Fake Anti-Virus's!
Cheers,
Peek
RE: Fake Anti-Virus's [How to know when you have one] - Quintus - 04-19-2010
A good tutorial. Mind if you add a header?
RE: Fake Anti-Virus's [How to know when you have one] - Atmosphere - 04-19-2010
Sure, I'll add a header soon.
Cheers,
Peek
RE: Fake Anti-Virus's [How to know when you have one] - daneasaur - 05-04-2010
Very helpful! Although personally I've never come across a fake antivirus.
Are they really "fake" antivirus' or are they just badly coded ones?
RE: Fake Anti-Virus's [How to know when you have one] - Rozzy - 05-04-2010
Nice guide.
I had one before, where it installed itself when I went onto a website, and it shut down my laptop, and when I turned it on, it'd be stuck on the anti-virus program whilst it was (?)hacking my files(?) :\
RE: Fake Anti-Virus's [How to know when you have one] - Don Panzer - 05-04-2010
Nice tutorial. Keep it up.
It was helpful for me.
RE: Fake Anti-Virus's [How to know when you have one] - Harvey - 05-04-2010
(05-04-2010, 04:11 AM)daneasaur Wrote: Very helpful! Although personally I've never come across a fake antivirus.
Are they really "fake" antivirus' or are they just badly coded ones?
They're fake - they claim to be an antivirus, by telling you that you're infected, but they're usually used either for promotion, or further infection.
RE: Fake Anti-Virus's [How to know when you have one] - rooneyful - 05-04-2010
i recently downloaded a torrent of KAV...now i think its a fake AV...
cuz ..it says its a BETA version..and moreover..when i enable it i am not able to access the internet..but i can download from Utorrent..
RE: Fake Anti-Virus's [How to know when you have one] - Harvey - 05-04-2010
(05-04-2010, 08:18 PM)rooneyful Wrote: i recently downloaded a torrent of KAV...now i think its a fake AV...
cuz ..it says its a BETA version..and moreover..when i enable it i am not able to access the internet..but i can download from Utorrent..
Please post a screenshot of the GUI.
RE: Fake Anti-Virus's [How to know when you have one] - --([-S7N-])-- - 05-06-2010
Add a list of names.
Code: * Advanced Cleaner
* AKM Antivirus 2010 Pro
* AlfaCleaner
* Alpha AntiVirus
* ANG Antivirus (knock-off of AVG Anti-virus)
* Antimalware Doctor
* AntiSpyCheck 2.1
* AntiSpyStorm
* AntiSpyware 2009
* Antispyware 2010
* AntiSpyware Soft
* Antivirus 7
* Antivirus Soft
* Antivirus Suite
* Antivirus System PRO
* AntiSpyware Bot from 2Squared Software
* AntiSpywareExpert[34]
* AntiSpywareMaster[35]
* AntiSpywareSuite[36]
* AntiSpyware Shield[37]
* Antivermins[38]
* Antivirus 2008[39]
* Antivirus 2009[40]
* Antivirus XP 2010[41]
* Antivirus 2010 (also known as Anti-virus-1)[42],[43]
* Antivirus 360[44]
* Antivirus Pro 2009[45]
* AntiVirus Gold [46]
* Antivirus Live[47],[48]
* Antivirus Master[49]
* Antivirus XP 2008[50]
* Antivirus Pro 2010[51]
* Avatod Antispyware 8.0[52]
* Awola[53]
* BestsellerAntivirus[54]
* Cleanator[55]
* ContraVirus[56]
* Control Center[57]
* Cyber Security[58]
* Doctor Antivirus[59]
* Doctor Antivirus 2008[60]
* DriveCleaner[61]
* Dr Guard[62]
* EasySpywareCleaner[63]
* eco AntiVirus
* Errorsafe[64]
* ErrorSmart
* Flu Shot 4[65][66] (probably the earliest well-known instance of rogue security software)
* Green Antivirus 2009[67]
* IE Antivirus (aka IE Antivirus 3.2)[68]
* IEDefender[69]
* InfeStop[70]
* Internet Antivirus (aka Internet Antivirus Pro, distributed by plus4scan.com)[71]
* Internet Security 2010[72],[73]
* KVMSecure[74]
* Live PC Care[75]
* MacSweeper[76]
* MalwareCrush[77]
* MalwareCore[78]
* MalwareAlarm[79]
* Malware Bell (a.k.a. Malware Bell 3.2)[80]
* Malware Defender (not to be confused with the HIPS firewall of the same name)[81]
* Malware Defense
* MS Antivirus (not to be confused with Microsoft Antivirus or Microsoft Security Essentials)[82]
* MS AntiSpyware 2009 (not to be confused with Microsoft AntiSpyware, now Windows Defender)[83]
* MaxAntiSpy[84]
* My Security Wall
* MxOne Antivirus[85]
* Netcom3 Cleaner[86]
* Paladin Antivirus
* PCSecureSystem[87]
* PC Antispy[88]
* PC AntiSpyWare 2010[89]
* PC Clean Pro[90]
* PC Privacy Cleaner[91]
* PerfectCleaner[92]
* Perfect Defender 2009[93]
* PersonalAntiSpy Free[94]
* Personal Antivirus[95]
* Personal Security[96]
* PAL Spyware Remover[97]
* PCPrivacy Tools[98]
* PC Antispyware[99]
* PSGuard[100]
* Privacy Center
* Rapid AntiVirus[101]
* Real AntiVirus[102]
* Registry Great[103]
* Safety Alerter 2006[104]
* Safety Center
* SafetyKeeper[105]
* SaliarAR[106]
* SecureFighter[107]
* SecurePCCleaner[108]
* SecureVeteran[109]
* Security Scan 2009 [110]
* Security Tool [111]
* Security Toolbar 7.1[112]
* SiteAdware
* Security Essentials 2010 (not to be confused with Microsoft Security Essentials)[113]
* Smart Antivirus 2009[114]
* Soft Soldier[115]
* SpyAxe[116]
* Spy Away[117]
* SpyCrush[118]
* Spydawn
* SpyGuarder
* SpyHeal (a.k.a SpyHeals & VirusHeal)
* SpyMarshal
* Spylocked
* SpySheriff (a.k.a PestTrap, BraveSentry, SpyTrooper)
* SpySpotter
* SpywareBot (Spybot - Search & Destroy knockoff, Now known as SpywareSTOP).
* Spyware Cleaner
* SpywareGuard 2008 (not to be confused with SpywareGuard by Javacool Software)[128]
* Spyware Protect 2009
* SpywareQuake
* SpywareSheriff (often confused with SpySheriff)
* Spyware Stormer
* Spy Tool
* Spyware Striker Pro
* Spyware Protect 2009
* SpywareStrike
* SpyRid
* SpyWiper
* SysGuard
* System Antivirus 2008
* System Live Protect
* SystemDoctor
* System Security
* Total Secure 2009
* Total Security
* Total Win 7 Security
* Total Win XP Security
* Total Win Vista Security
* TrustedAntivirus
* TheSpyBot (Spybot - Search & Destroy knockoff)
* UltimateCleaner
* VirusHeat
* VirusIsolator
* Virus Locker
* VirusProtectPro (a.k.a AntiVirGear)
* VirusRemover2008
* VirusRemover2009
* VirusMelt
* VirusRanger
* Virus Response Lab 2009
* VirusTrigger
* Vista Antispyware 201
* Vista Antivirus 2008
* Vista Internet Security 2010
* Vista Smart Security 2010
* Volcano Security Suite
* Win 7 Antivirus 2010
* WinAntiVirus Pro 2006
* WinDefender (not to be confused with the legitimate Windows Defender)
* Windows Police Pro
* Windows Protection Suite
* WinFixer
* WinHound
* Winpc Antivirus
* Winpc Defender
* WinSpywareProtect
* WinWeb Security 2008
* WorldAntiSpy
* XP AntiMalware
* XP AntiMalware 2010
* XP AntiSpyware 2009
* XP AntiSpyware 2010
* XP Antivirus 2010
* XP Antivirus Pro 2010
* XP Defender Pro
* XP Internet Security
* XP Security Tool (not to be confused with Security Tool.)
* XP-Shield
* Your Protection
* Zinaps AntiSpyware
Disregard the numbers in the []'s. Taken from Wikipedia.
A list can also be found here: http://www.spywarewarrior.com/rogue_anti-spyware.htm
|