The RDV Group
   Safe Computing Experts

  Home    Books    Services    Security News    Resources    About
 
 
Security News
Search Security Channel
Infoworld Security News
CNET Security News
eWeek Security News
Windows Security News
Security Tracker
Security Focus Vulns
Security Focus News
NYTimes Tech News
BBC Technology News
NewsFactor Tech News
RootSecure.net
Spyware News
CastleCops
EFF Breaking News
Security Fix
SC Magazine
CSO Magazine
Network Computing

Copyright © 2004 The RDV Group Inc.

Newest additions and updates of spyware parasites
Latest information about spyware threats to your computer. Get new and updated information how to detect and remove spyware and protect your PC from parasites.

Security Suite
Security Suite is a rogue anti-spyware program from the same family as AV Security Suite and Antivir Solution Pro. The rogue program states that your computer is infected with adware, spyware and other viruses that may steel your sensitive information or even make your PC unusable. Security Suite reports false system security threats and infections to scare you into thinking that your computer is infected with malware. It then prompts to pay for a full version of the program to remove the infections. Don't buy this rogue program, it will give you a false sense of security and nothing more. Instead, please use the removal instructions below to remove Security Suite from your computer as soon as possible. SecuritySuite is promoted mainly through the use of Trojans. Once installed, the rogue program will scan your computer and state that there are several critical and high risk threats that should be removed from the system immediately. As a typical rogue program it won't let you to remove the infections unless you first purchase it. What is more, it will constantly display fake security alerts about serious system threats and critical infections. Fake Security Suite alerts: Antivirus software alert INFILTRATION ALERT Your computer is being attacked by an internet virus. It could be a password-stealing attack, trojan - dropper or similar. Threat: BankerFox.A Do you want to block this attack? Yes or No Windows Security Alert Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now. It will also terminate pretty much all other applications on your computer and state that they are all infected. Furthermore, it will configure Windows to use a a proxy server, so that you won't be able to open any other websites except those related to Security Suite scareware. Last, but not least, this rog...

AV Security Suite
AV Security Suite is a rogue anti-spyware program from the same family as Antispyware Soft and Antivirus Soft. Once installed, this fake program will display fake security alerts and state that your computer is infected with spyware, adware and other types of malware. Then it will prompt you to pay for a full version of the program to remove the infections and to make your computer more secure. Of course, that's not true, because AV Security Suite is an infection itself and obviously won't protect your computer from malware. Most importantly, don't purchase this bogus program. If you have already purchased it, then you should contact your credit card company and dispute the charges. Finally, please follow the removal instructions below to remove AV Security Suite from your computer as soon as possible either manually or with an automatic removal guide. Probably the most annoying thing about AVSecuritySuite is that it actually blocks legitimate software and certain system tools. It may even make your computer very slow. When running, it will display several fake pop-ups and state that your anti-virus or anti-spyware program is infected and that you should uninstall it. Furthermore, it will impersonate Windows Security Center and state that your computer is not protected against malware. It will then recommend you to buy a full version of AV Security Suite. Again, don't do that, otherwise you will simply lose your money. It's very important to mention that you may have to reboot your computer is safe mode with networking in order to remove this virus from your computer. AV Security Suite Basic changes Internet Explorer settings and enables proxy server. You need to restore those settings, otherwise, you won't be able to download malware removal tools from the Internet. If you fins that your computer is infected with this bogus and very annoying program, then please follow the removal instructions below. AV S...

SP Center
SP Center is a rogue anti-spyware program from the same family as Privacy Center and Control Center. Most of the time, it comes from fake online scanners and infected web pages. This rogue program can come bundled with other malware too through software vulnerabilities. Once installed, it will pretend to scan your computer for viruses and then will report false scan results. It will claim that your computer is compromised and infected with various malware, viruses, Trojans, spyware and adware. Finally, it will prompt you to register the rogue program in order to remove found infections and to protect your computer against emerging threats. However, SP Center is a scam and it won't protect your computer against any security threat. Please remove SP Center from your computer upon detection using the removal instructions below. And, of course, you shouldn't purchase it. If you have already bought this bogus program then you should contact your credit card company and dispute the charges. Another very annoying thing about SPCenter is that it hijack web browsers and display misleading messages while surfing the web. It claims that certain websites are infected, compromised or may harm your computer. It will block security related websites. What is more, SP Center will block legitimate anti-spyware programs and disable system utilities to make the removal process more complicated. You may have to reboot your computer in safe mode with networking, download an automatic removal tool from this page and run a full system scan. Please follow detailed SP Center removal instructions below.

Windows Defence
Windows Defence is a rogue anti-spyware program that reports false system security threats and claims that your computer is infected with malware. Basically, it's a rename of Defence Center which is of course a rogue program too. Windows Defence is promoted through the use of fake online scanners and infected websites. Once installed, it will pretend to scan your computer for viruses and then claim that it has found infected files that should be removed from the system immediately. If you choose not to remove these supposedly found infected files then the rogue program will display fake security warnings on your computer screen. The scan results are false, so you can safely ignore them. It goes without saying that you shouldn't purchase this bogus program. Instead, please follow Windows Defence removal instructions below. You can remove Windows Defence from your computer manually but we strongly recommend you to use an automatic removal tool simply because there might be other malware installed on your computer. Besides, it it will probably state that you can't remove infected files manually but will block legitimate anti-spyware and anti-virus programs at the same time. It will also hijack Internet Explorer and claim that you can't visit certain websites because they are infected. This fake program may even claim that such websites as facebook.com are phishing sites. That sound ridiculous but WindowsDefence does all its best to trick you into paying for a full version of the program. You may have to reboot your computer is safe mode and run a system scan with malware removal tool. The rogue program disables system restore too. The main website of this rogue is windows-defence.com (please don't visit this site). As you can see, Windows Defence is nothing more but a scam. It detects non-existent files as infections and forces to pay for removal. If you find that your computer is infected with this scareware please use...

Defence Center
Defence Center is a rogue anti-spyware program from the same family as Windows Defence malware. Once installed, the rogue program will claim that your computer is infected with viruses, spyware and other malicious software. As a typical scareware, it will constantly display fake security alerts about security threats and prompt you to pay for a full version of the program remove supposedly found malware from your computer. Defence Center is worthless program. It won't be able to protect your computer against viruses. This program is a scam, don't fall victim to this bogus program. Instead, please use the removal instructions below to remove Defence Center from your computer either manually or with an automatic removal tool. While DefenceCenter is running, it will pretend to scan your computer and then report fake infections that supposedly can be removed only with a full version of the program. Furthermore, it will display fake security alerts and notifications from windows task bar claiming that there are many security threats on your PC. Last, but not least, the rogue program will block legitimate anti-spyware and anti-virus programs to protect itself from being removed. It may block task manager and registry editor as well. Also, it will hijack web browsers and redirect you to its main website which is defence-center.com (please don't visit this website). As you can see, Defence Center has only one goal - to trick you into purchase the program. If you find that your computer is infected with this malware please get rid of it as soon as possible. Please follow Defence Center removal instructions below. Finally, if you have already purchased it then call your credit card company and dispute the charges.

Total PC Defender
Total PC Defender is a fake antivirus program. Please read Total PC Defender 2010 removal instructions carefully and remove this virus from your computer as soon as possible. The rogue program is from the same family as Desktop Defender 2010. More generally speaking, it's nothing more but a typical rogue application that displays misleading security alerts and reports false system security threats to make you think that your computer is infected with Trojans, worms and other malicious software. When running, it will imitate a system scan and display numerous infections. Of course, scan results are false. Then it will ask you to pay for a full version of the program in order to remove the infections which actually do not even exist. [Figure 1. Total PC Defender graphical user interface] What is more, Total PC Defender will constantly display fake security alerts stating that your computer is under attack or seriously infected. It will also claim that malicious programs that may steal your private information were detected. The fake notification states: Security Warning! Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer. Click here to clean your PC immediately. There are more fake warnings and you will likely see all of them if your computer is already infected. However, false scan results and fake security alerts are not the biggest problem. The most annoying thing is that Total PC Defender blocks particular software and disables important system tools or options. It can disable system restore and block safe mode too. In some cases it will block all executable (.exe) files, so you won't be able to launch any anti-spyware software or malware removal tool. Try to download and run an automatic removal tool from this page (provided below). If you can't, then read further instructions. First of all, you have to end the main process of Total PC Defender w...

WorldAntiSpy
WorldAntiSpy is a rogue security tool. It uses misleading ways to gain a purchase. WorldAntiSpy infiltrates computers secretly and then it simulates a security tool. WorldAntiSpy displays exaggerated scan reports and security warnings to make an image of badly infected system. It displays pop-ups till user purchases the full version of this malware. WorldAntiSpy is useless and unreliable application. It may be a security risk as well.

Antimalware Doctor
Antimalware Doctor is a rogue anti-spyware program that displays fake security alerts and reports false scan results to make you think that your computer is infected with malware. This fake program is promoted and installed through the use of trojan viruses that usually come from fake online scanner and various bogus websites. Once installed, Antimalware Doctor will run a fake system scan and display a list of fake threats and infections.Then, it will claim that you must purchase the program in order to remove the infections. Don't buy it! This is nothing more but a scam. Instead, please use the removal guide below to remove Antimalware Doctor from your computer either manually for free or with an automatic removal tool. [Figure 1. Antimalware Doctor graphical user interface] While running, AntimalwareDoctor will display numerous fake security alerts and notifications from Windows Task bar. Those alerts will state that your computer is subjected to hacker attack or that somebody is trying to transfer your private data via internet. Please ignore such fake warnings. Antimalware Doctor just tries to scare you and trick you into purchasing the program. Warning! Removed attack detected! Antimalware Doctor has detected that somebody is trying to block your computer remotely via {Trojan Worm BX12.434.CardStoler}. Transfer for Your private data via internet will start in: 7 We strongly recommend you to block attack immediately. Your computer is subjected to hacker attack. Antimalware Doctor has detected that somebody is trying to transfer your private data via internet. We strongly recommend you to block attack immediately. Antimalware Doctor has detected that somebody is trying to transfer your private data via internet. We strongly recommend you to block attack immediately. What is more, AntimalwareDoctor will block legitimate anti-virus and anti-spyware programs and security related websites. You will have to end its processes in order to use removal...

GamesBar
GamesBar is a free toolbar for Internet Explorer that provides many free online games. However, it can be classified as an adware application, because it constantly displays advertising banners and very annoying popups. What is more, GamesBar may tracks your personal information and pass it on to third parties, without your authorization or knowledge. If you find that your computer is infected with GamesBar, please use the removal guide below to remove it for free.

Security Tool
Security Tool is a rogue antivirus application that deliberately gives reports of false system security threats on your computer and displays fake security alerts or notifications to make you think your PC is infected with malware. The misleading application is from the same family as Total security 2009 and System Security. When installed, SecurityTool will be configured to start automatically when you log on into Windows. Then it will imitate system scan and display a variety of infections that can't be removed unless you purchase the program. The files detected during the scan are either harmless or legitimate system files and can't cause any damage to your computer. Security Tool is pushed through the use of Trojans, fake online anti-malware scanners and other malicious software. It is installed along with Trojans FakeAV that display fake security warnings and promote SecurityTool malware. Once running, the bogus program will block legit programs and especially anti-virus software. Another interesting thing is that if you click on Updates button, you will see "Updating", but actually there is no network activity. It's just another argument why Security Tool is classified as a rogue security application. What is more, this parasite will impersonate Windows Security Center and constantly display warnings/notifications about serious security threats and privacy issues. It may claim that your computer is under attack by an Internet virus or that private data can be stolen. For example: "Security Tool Warning Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs. Click here to remove it immediately with SecurityTool." To make things worse, SecurityTool will hijack web browsers and block certain security websites obviously to protect itself from being deleted. It should be already obvious that this p...

Trojan.Agent
Trojan.Agent is not a threat in itself, it is a fake threat displayed by rogue anti-spyware programs. These programs use this and other scare tactics to get the user to buy the full version of the fake spyware removal programs. Programs related to Trojan.Agent should not be trusted under any circumstances and should be removed upon detection.

PC MightyMax
PC MightyMax can be classified as fake and useless diagnostic tool, because it can be difficult to exit without purchasing the full version of this product. It seems that PC Mighty Max was design to periodically display pop-up windows and distracting alerts in order to scare users hopping that they will buy this worthless application. PC MightyMax runs automatically when computer starts, and there is no easy way how to change this behaviour. What is more, it has no setting to allow users to disable this function. Every few hours, PC MightyMax displays "CRITICAL ALERT" and "Alert!!!" pop-up windows that are mainly advertisements for the full version of the this software. These officious alerts can even make beeping noises decreasing user's ability to work with his computer. Summing-up, PC MightyMax may be considered as unwanted application which should be removed without consideration.

"Application can not be executed" Security Warning
You may see "Application can not be executed" Security Warning when your computer is infected with a rogue anti-spyware application or other malicious software. Malware blocks legitimate software (especially anti-virus) and states that the requested file is infected (usually an executable file). Then it asks whether you want to activate antivirus software (fake) or not. If such error occurs, you should end malware processes with task manager. If task manager is blocked too, then use Process Explorer. Then try to run your anti-virus/spyware software again. [Figure 1. Application can not be executed Security Warning] Security Warning Application can not be executed. The file [file name].exe is infected. Do you want to activate your antivirus software now?

Win7 AV malware warning page

Win7av.com
Win7av.com is a rogue website that promotes misleading antivirus software called Win7 AV. It looks very close to the Microsoft Security Essentials web page. People who created this misleading website copied Microsoft Security Essentials awards, graphical elements and pretty much every other design element from the genuine website microsoft.com/security_essentials. Win7av.com claims that Win7 AV is the best antivirus solution on the market. That's obviously not true. But it definitely looks genuine and can actually trick many users into purchasing the rogue program. If you find that your computer is infected with Win7 AV please use the removal guide below.

Win7 AV
Win7 AV is a rogue antivirus program that claims to scan your computer for malware and then reports false system security threats and displays misleading malware alerts. Finally, it advises to pay for a full version of the program to remove the infections which don't even exist on your computer. Win7 AV is a typical rogue program but we have to admit that it looks very genuine. It's promoted through the use of Trojans, misleading websites, fake online scanners and fake web pages that also look very legitimate. Once installed, Win 7 AV will pretend to scan your computer and claim that there are numerous infections on your PC that can be removed only with a full version of the program. To make things even worse, it will constantly display fake security alerts. The text of some of these alerts are: "Scanning is complete. 4 infections were found, would you like to remove all? Sdbot.add DvFuCa Angerfire" "New threads were found There are 4 undeleted threads. To remove all threads click to Remove All at main window." If you choose not to purchase Win7 AV will display these fake security alerts like every one or two minutes. What is more, the rogue program will block legitimate anti-spyware and anti-virus programs. If you choose to purchase it (obviously you shouldn't do this), then you will be redirected to a pay page of this misleading application which is win7av.com. It impersonates to the Microsoft Security Essentials webpage. As you can see, Win7 AV is nothing more but a scam. Don't buy it. If you have already purchased it then please contact your credit card company and dispute the charges. The please follow our removal guide to remove Win7 AV from your computer either manually or with an automatic removal tool.

Ultraview
Ultraview is a computer surveillance program that logs user keystrokes, takes screenshots, captures e-mail messages and online chat conversations and records web sites visited. Gathered data can be transferred to a configurable remote host. It can also be accessed via the Internet. Ultraview is able to hide its running processes and avoid detection. The threat runs on every Windows startup.

Crawler
Crawler is an Internet Explorer toolbar that provides a pop-up blocker, additional search functions, links and other useful features. However, it also redirects web searches and changes the Internet Explorer default error page. Crawler must be manually installed. It runs every time the user launches Internet Explorer.

SpyDefender 2010
SpyDefender 2010 is a rogue anti-spyware program from Russia that deliberately reports false system security threats and claims that your computer is infected with spyware, Trojans, worms and other viruses. It will use other misleading methods too to scare you into purchasing the program. This is the main goal of this scareware. Spy Defender 2010 a typical rogue program but it's not the most aggressive one and besides it targets internet users mainly from Russia. Of course, in theory it may infect any computer connected to the Internet. Once installed, SpyDefender 2010 will pretend to scan your computer for malware and then report numerous infections. In reality, though, the scan results are absolutely false. It has a file called bases.dat with more that two hundred malware names on it and randomly displays some of the names in its false security alerts. SpyDefender 1.2 is promoted mostly through the use of Trojans and various misleading websites. Spy-defender.com is the home page of this fake anti-spyware program. Please don't visit that site because it hosts malware. As you can see, SpyDefender 2010 is nothing more but a scam. It claims that your computer is infected and asks for money to remove non-existent infections. Please remove SpyDefender 2010 from your computer upon detection. You can remove it either manually or with an automatic removal tool.

Sdbot.add
Sdbot.add is a dangerous widely spread worm that propagates mostly through unprotected network shares found on a local network. Once executed, the parasite drops a rootkit that allows the remote intruder to break into the infected system. Sdbot.add also runs a backdoor controlled through the IRC network. This backdoor gives the attacker unauthorized remote access to a compromised computer and allows to control it. Sdbot.add secretly runs on every Windows startup.

Last Update:

Get the CISSP Prep Guide 2nd Edition!

Valuable Wireless Security Information!

Pass the CompTIA Security + Exam!

 

About    Bios    Contact    Partners    Privacy Statement