Today at Lavasoft, we discovered a number of new clones from the XpAntispyware2010 family of rogue security software. The unique aspect of this family is the ability to randomly change its name. Lavasoft Malware Labs found 36 different names on three operating systems (Windows XP, Windows Vista and Windows 7).

The links below lead to snapshots in the Lavasoft Rogue Gallery:

 

Windows XP

antispywarexp
antivirusxp
totalxpsecurity
xpdefender
xpdefenderpro
xpsecuritytool2010
xpsmartsecurity
xpsmartsecurity2010
xpantimalware
xpantimalware2010
xpsecurity
xpsecuritytool

Antivirus7 is a new rogue anti-virus application. It is a clone of the rogue Antivir.













CleanUpAntivirus is a new rogue anti-spyware application. It is a clone of the SmartVirusEliminator family.














New Rogue: SmartSecurity

by Albin on March 10th, 2010 in Rogues, Security Alert.

A clone of the annoying and well spread rogue SecurityTool has now been released. It's hosted on a Russian domain and is named SmartSecurity.

VirusProtector is the latest (fourth) generation of the WiniGuard rogue anti-malware family.














New Rogue: DrGuard

by LS Anders on March 3rd, 2010 in Rogues, Security Alert.

DrGuard is a new rogue anti-virus application. It is a clone of PaladinAntivirus.














A word of caution: Microsoft has issued a warning on an unpatched vulnerability that could affect users of Windows 2000, Windows XP, and Windows Server 2003, running Internet Explorer.

“The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer,” the security advisory reads. “If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed…”

DesktopSecurity2010 is a new rogue anti-spyware application. It is a clone of DesktopDefender2010.















SecurityEssentials2010 is a rogue anti-spyware application. It is a clone of InternetSecurity2010.














A new clone from the MalwareCatcher rogue security software family has now been released. 

The fraud tool is called SecurityAntivirus and will add hundreds of registry keys within:

PaladinAntivirus is a new rogue anti-spyware application. It is a clone of ProtectionSystem.














New Rogue: Antivirus

by Albin on February 8th, 2010 in Rogues, Security Alert.

A new rogue security product was found by Lavasoft Malware Labs this afternoon (UTC+01:00 - Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna). It's called Antivirus and will show a long list of false positives to entice victims into buying the fraud tool.

© 2010 Lavasoft. All rights reserved.