May 16th, 2008 | Posted in Rogue Anti Spyware, XP Security Center, XPSecurity Center, XPSecurityCenter
XP SecurityCenter Threat Level: 
XP SecurityCenter is another rogue anti-spyware application, trying to ride off the name of Window’s legitimate XP Securitycenter software. Just like fake anti-spyware IE Defender — which XP SecurityCenter is related to — , XP SecurityCenter may pop up exaggerated security alerts to try and trick you into buying XP SecurityCenter for $44.95, at XPSecurityCenter.com
What a deal.
Remove XP SecurityCenter, if only because XP SecurityCenter may make you want to toss your PC out the window.
Read more about XP SecurityCenter »
May 15th, 2008 | Posted in Advanced XPDefender, AdvancedXP Defender, AdvancedXPDefender, Rogue Anti Spyware
Advanced XP Defender Threat Level: 
Advanced XP Defender is more fake anti-spyware, a clone of WinIFixer. Advanced XP Defender runs fake “security” scans and pops up exaggerated security alerts to try and trick you into buying Advanced XP Defender. These Advanced XP Defender popups read:
Malware and harmful software were found
Online scanner detected software [SIC] may compromise your privacy or damage your computer
The only “malware and harmful software” you’re infected with is Advanced XP Defender. Skip wasting $49.95-99.95 at AdvancedXPDefender.com –
It’d make more sense to just throw your PC against the wall.
Read more about Advanced XP Defender »
May 15th, 2008 | Posted in Adware, Virtu Monde, VirtuMonde, VirtueMonde, Virtumond, Virtumonde . DLL, Virtumonde.C, Virtumondo
VirtuMonde Threat Level: 
VirtuMonde is adware that launches annoying popup ads on your PC. VirtuMonde popups pimp fake anti-spyware like SysDefender, WinFixer, and ErrorSafe. VirtuMonde can also act as a keylogger, and record every keystroke you type, save this information as a DLL file (virtumonde.DLL, perhaps?), and send it to a parent site, putting your personal and financial information at risk.
VirtuMonde is also known as Virtumonde.C, and “major rip-off.”
Read more about VirtuMonde »
May 14th, 2008 | Posted in Rogue Anti Spyware, XP-Sheild 2.1, XPShield 2.1
XP-Shield 2.1 Threat Level: 
XP-Shield 2.1 is more fake anti-spyware. XP-Shield 2.1 runs fake “security” scans and pops up exaggerated security alerts to try and trick you into buying XP-Shield 2.1. These XP-Shield 2.1 popups read:
Windows has detected virus or spyware activity on your computer. It is strongly recomnded that you obtain antivirus and antispyware protection software. Windows will now perform a search for installed antivirus and antispyware applications.
Found antivirus/antispyware:
XP-Sheild… UNREGISTERED VERSION
Continue Unprotected [or] Get Full version of XP-Shield Now!
Remove XP-Shield 2.1, if only because XP-Shield 2.1 may make you want to throw your PC out the window.
Read more about XP-Shield 2.1 »
May 13th, 2008 | Posted in Anti Malware Guard, Anti MalwareGuard, AntiMalware Guard, AntiMalwareGaurd, Rogue Anti Spyware, Trojans
AntiMalwareGuard Threat Level: 
AntiMalwareGuard is just more fake anti-spyware. AntiMalwareGuard may have been installed by a Trojan. AntiMalwareGuard launches fake system alerts. This AntiMalwareGuard popup is supposed to scare you into buying the fake antispyware. It reads:
“It is highly recommended to get a full version of AntiMalwareGuard protection software in order to fix all malicious codes. Click here to start registration and have all the malware away from your PC thereafter.”
It is highly recommended unless you like getting ripped off, don’t download AntiMalwareGuard. If you already paid for this piece of crap, you can try AntiMalwareGuard.com’s refund policy. But if I had a choice between dealing with them and throwing my PC out the window, I think you know what I’d do.
Read more about AntiMalwareGuard »
May 13th, 2008 | Posted in Browser Hijackers, Myzor FK@yf, Rogue Anti Spyware, W32 Myzor FK@yf, W32.Myzor.FK@yf
W32.Myzor.FK@yf Threat Level: 
W32.Myzor.FK@yf is a fake virus that appears in popups by browser hijackers (think PureSafetyHere.com). W32.Myzor.FK@yf popups are trying to scare you into buying rogue anti-spyware, such as AntiSpyware Shield, XP Antivirus 2008, and WinSpyKiller. This W32.Myzor.FK@yf popup reads:
Warning! W32.Myzor.FK@yf is a virus that infects files with .exe extensions. It attempts to steal passwords and private information from the infected computer.
Type: Virus
Infection Length: 138,293 bytes
Systems Affected: Windows 95, 98, ME, NT (all versions), 2003, Windows XP (all service packs)
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical details: Creates files in %Windir%\ directory. By default, this is C:\Windows.
Adds values to registry keys: HKEY_LOCAL_MNACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Scans the hard drive for .exe files and infects any executable files. Searches for passwords/information, which it may send to a remote attacker.
Recomendations [SIC]: Click “OK” to download officially approved security software.
Always keep your patch levels up-to-date.
Always keep a healthy skepticism would be a better recommendation.
You’re not infected with W32.Myzor.FK@yf: you’re infected with fake anti-spyware.
Read more about W32.Myzor.FK@yf »
May 13th, 2008 | Posted in Malware Scanner, MalwareScaner, Rogue Anti Spyware
MalwareScanner Threat Level: 
MalwareScanner is more fake anti-spyware.
You have to manually download MalwareScanner. Once you make that mistake, MalwareScanner tries to scare you into buying it with MalwareScanner popups and exaggerated scans. Unless you like getting ripped off, don’t buy MalwareScanner.
Read more about MalwareScanner »
May 12th, 2008 | Posted in Dangerous Virus, DanjerousVirus, Rogue Anti Spyware, Trojans
DangerousVirus Threat Level: 
DangerousVirus is a “virus” that appears in fake security alerts from rogue antispyware. DangerousVirus popups could read:
“Your computer was infected with DangerousVirus.
It’s dangerous for your system, some files can be lost and your browser can be slow!
Click OK to download the antispyware program to clean your computer! (Recommended)”
or
“Your browser was hijacked by DangerousVirus.”
This DangerousVirus popup is supposed to scare you into buying the fake antispyware. You may have caught “DangerousVirus” by a drive-by download, or getting tricked into downloading a fake video codec.
Unless you like getting ripped off, don’t download the software the DangerousVirus popup links to. You’re not really infected with DangerousVirus — you’re infected with fake anti-spyware that you need to remove.
Read more about DangerousVirus »
May 12th, 2008 | Posted in Keyloggers, SpieMan, Spy Man, Spyware SpyMan
SpyMan Threat Level: 
SpyMan is a keylogger that tracks your emails, chats, instant messages, and keystrokes typed. SpyMan might have been installed for legitimate purposes — like monitoring children’s Internet safety — but SpyMan may be catching your username and passwords for accounts, tracking your online conversations, watching which websites you visit, seeing what applications you launch, and more. SpyMan might be a serious violation of your security and privacy, putting your financial and personal data at risk.
I suggest removing SpyMan immediately.
And dumping whoever installed SpyMan onto your PC.
Read more about SpyMan »
May 12th, 2008 | Posted in Browser Helper Object, Browser Hijackers, Pvnsmfor Tool bar, PvnsmforToolbar, Rogue Anti Spyware
Pvnsmfor Toolbar Threat Level: 
Pvnsmfor Toolbar is another toolbar by Trojan Zlob, created to scare you into buying fake anti-spyware To scam you, Pvnsmfor Toolbar pops up annoying ads, hijacks your home page, and hopes you’ll click Pvnsmfor Toolbar’s buttons for “Remove Popups, Scan Spyware, Security Test, and Spam Protection.”
Obviously, its name makes it clear — Pvnsmfor Toolbar isn’t very marketing savvy.
If you have Pvnsmfor Toolbar, your search results could be topped with this fake alert:
“Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware…”
Warning: the only thing you’re really infected with is Pvnsmfor Toolbar. Unless you like wasting money, don’t buy Pvnsmfor Toolbar or the products it’s pimping.
Read more about Pvnsmfor Toolbar »