The RDV Group
   Safe Computing Experts

  Home    Books    Services    Security News    Resources    About
 
 
Security News
Search Security Channel
Infoworld Security News
CNET Security News
eWeek Security News
Windows Security News
Security Tracker
Security Focus Vulns
Security Focus News
NYTimes Tech News
BBC Technology News
NewsFactor Tech News
RootSecure.net
Spyware News
CastleCops
EFF Breaking News
Security Fix
SC Magazine
CSO Magazine
Network Computing

Copyright © 2004 The RDV Group Inc.

Newest additions and updates of spyware parasites
Latest information about spyware threats to your computer. Get new and updated information how to detect and remove spyware and protect your PC from parasites.

AV Security Essentials
AV Security Essentials is a rogue anti-spyware program that displays fake security alerts and reports false malware infections to make you believe your computer is infected with spyware and similar stuff. The rogue program is a clone of Smart Anti-Malware Protection scareware and it is promoted mostly through the use of Trojans and fake online virus scanners. Scammers may also promote their bogus software on popular social networks and instant messengers. Once installed, AV Security Essentials will run a fake system scan and display a list of non-existent malware infections. The scan results are completely false, so you may safely ignore them. The rogue program may detect legitimate programs and files as infections as well. For example, AV Security Essentials may claim that Internet Explorer (iexplore.exe) is infected by notorious Blaster worm. This is not true. That's why you shouldn't follow on screen instructions. Instead, please use the removal instructions below to remove AV Security Essentials from your computer safely.When running, AV Security Essentials will display numerous fake and very annoying security alerts claiming that your computer is compromised or infected and that you should activate AV Security Essentials to ensure full system protection against the latest malware threats. This fake program will blocks legit antivirus and anti-spyware programs to protect itself from being removed. It may block those programs in Safe Mode too. It will claim that your anti-virus or any other program actually is infected. If you find that your computer is infected with AV Security Essentials, please follow the removal instructions below. And of course, don't purchase it. This is nothing more but a scam. However, if you have already bought it then you should contact your credit card company and dispute the charges as soon as possible. To make the removal procedure easier, you can activate this rogue application using this fake registra...

AntivirusGT
AntivirusGT is a rogue anti-spyware program from the same family as Antivirus 7. It attempts to convince you to purchase software in order to remove non-existent malware from your computer. Once installed, this rogue program reports many false system security threats and randomly displays fake security warnings to make you think that your computer is infected with spyware, adware, Trojan Horses and other malicious software. Cyber criminals promote their bogus software in various ways. They send spam emails that contain malicious links or attachments; they also spam blogs and forums with links to adult videos and pirated software. There are also fake pages containing exploits, fake torrent files, malicious banner advertisements and etc. AntivirusGT disables Task Manager, Registry Editor and other system tools. Of course, it blocks anti-virus and anti-malware programs and security related websites too. Actually, this fake program blocks nearly all websites and each time displays fake messages "Internet Explorer unable to display webpage" and "This website has been reported as unsafe". Attention! Your web page request has been cancelled.This web site refused your connection as it was reported as a malicious request. This can be caused by Viruses, Trojans or Malware installed on your computer.In order to resend your request to the website, press Resend request (please note, this action may cause a permanent block of your computer by the requested website)In order to activate your security software, please press Fix Now (recommended)AntivirusGT Resident Shield: Virus DetectedWarning! Active virus detected!Threat Detected: Trojan.Injector.BZInfected File: C:WindowsSystem32rundll32.exeAs you can see, AntivirusGT is nothing more but a scam. It uses various misleading methods to trick you into purchasing the program. If you are reading this article, then your computer is probably infected with this malware. Again, don&#...

XP Security Tool 2010
XP Security Tool 2010 is a rogue virus protection program. It reports false scan results and fake security alerts to scare you into purchasing this rogue program. XPSecurityTool2010 claims that your computer is infected with worms, trojans, adware or other malware and that you should purchase XP Security Tool 2010 to remove the infections that actually don't even exist. Most of the time, this fake program comes from fake or infected video sites or fake online scanners. But may be also promoted on such popular sites as Facebook or MySpace with a name of XP Security Tool 2011.Once active, this parasite will supposedly scan your computer and report numerous fake infections or system security threats. It will also flood your computer with very annoying pop-ups and fake security alerts claiming that your computer is infected or under attack and that your data can be deleted. That's a part of whole scan so you shouldn't worry to much about those fake alerts and pop-ups. What is more, XP Security Tool 2010 will block almost all programs on your PC to protect itself from being deleted. It goes without saying that it will block security software in the first place. The rogue program also uses browser hijacking and redirects users to various misleading site that promote rogue programs or display false advertisements. Without a doubt, you should remove either its XP Security Tool 2010 or XP Security Tool 2011 from your computer upon detection. Please read the removal instructions below carefully. XP Security Tool 2010 removal instructions:1. Click Start->Run (or WinKey+R). Input: "command". Press Enter or click OK.2. Type "notepad" as shown in the image below and press Enter. Notepad will open.3. Copy and past the following text into Notepad:Windows Registry Editor Version 5.00[-HKEYCURRENTUSERSoftwareClasses.exe][-HKEYCURRENTUSERSoftwareCl assessecfile][-HKEYCLASSESROOTsecfile][-HK...

Windows Shield Center
Windows Shield Center is a rogue antispyware application that fake errors to make you think that your computer is infected with viruses and has some other problems. It's promoted through the use of Trojan that impersonates the fake Microsoft Security Essentials Alert. Windows Shield Center is also distribute via fake online scanners. Once installed, Windows Shield Center will pretend to scan the computer and report many system problems and infections to scare you into purchasing the rogue program. Do not purchase it. Instead, please use our removal instructions below to remove Windows Shield Center from your computer using spyware removal tool or manually.Windows Shield Center blocks other programs on the compromised computer. It blocks web browsers and Windows utilities stating that they are infected and may cause serious damage to the system. Windows Shield Center states that your sensitive data is at risk, privacy is compromised and Internet security disabled.System component corrupted!System reboot error has occurred due to lsass.exe system process failure.This may be caused by severe malware infections.Automatic restore of lsass.exe backup copy completed.The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.Windows Shield Center is a scam. It displays fake error messages and security alerts to make you think that your computer in infected. Then it prompts to pay for a full version of the program to clean up the computer. Please use the removal guide below to remove Windows Shield Center.

Windows Inviolability System
Windows Inviolability System is a rogue program that pretends to be a computer optimization utility. The rogue program comes from fake online scanners or through the use of Trojans that pretend to be Microsoft Security Essentials Alert. Once installed, Windows Inviolability System will pretend to scan the computer for various problems and errors and after the fake scan it reports overall system score which is obviously low to scare the user into thinking that there is something from with your computer. If the user chooses to fix the supposedly found errors, he will be prompted to install additional module. This module is not free. What we have here is a typical scam. User is promoted to pay for useless software. Do not buy it. Instead, please use our removal instructions below to remove Windows Inviolability System malware from your computer manually or with an automatic removal tool. Windows Inviolability System blocks other programs on the compromised computer. It blocks web browsers and Windows utilities stating that they are infected and may cause serious damage to the system. It displays fake security alerts and notifications too. Windows Inviolability System states that your sensitive data is at risk, privacy is compromised and Internet security disabled. As you can see, Windows Inviolability System is nothing more but a scam. It displays fake error messages and security alerts to make you think that your computer in infected. Then it prompts to pay for a full version of the program to clean up the computer. Please use the removal guide below to remove Windows Inviolability System from the system as soon as possible. We strongly recommend you to use anti-spyware software to remove the rogue program and related malware.

QuickHealCleaner
QuickHealCleaner is a rogue security application that reports false or exaggerated system security threats and displays fake security alerts to trick you into purchasing the program. The rogue application is from the same family as SystemCop, BlockDefense, SaveDefense, Trust Ninja, SaveSoldier. Once installed, it will list a variety of infections and then prompt you to pay for a full version of the program to remove non-existing system security threats. Do not purchase this program and uninstall QuickHealCleaner from your computer upon detection. Quick Heal Cleaner is promoted through the use of Trojans and other malicious software. It enters a computer without user's consent and knowledge. However, this misleading application can be downloaded and installed manually as video codecs or drivers. Attention!!! Don't mix it with Quick Heal antivirus, because this one is legal and does not pose any harm! While active, Trojans display fake security alerts and notifications from Windows Task bar. Usually Trojans state that your computer is under attack or that your antivirus software is disabled. Then they suggest purchasing QuickHealCleaner which will supposedly provide full system protection. Fake security alert reads:"Your system is at risk of being hijacked or damaged. Harmful software is currently running. These active processes may lead to the leak of your personal data and the extermination of your machine."While running, QuickHealCleaner will simulate system scan and display various bogus infections just to scare you. What is more, it will constantly display fake security alerts about serious infections and system errors. You will also see warnings about privacy violations. Do not trust this program. It's nothing more but a scam. Please use the removal guide below to remove QuickHealCleaner from the system manually for free.

Windows Express Help
Windows Express Help is a fake security program that enters computers via Trojans in order to rip users off. Fake scan results is a method to scare you into purchasing the program. You should remove Windows Express Help from your computer as soon as possible. Please use the automatic removal tool below. The rogue program will constantly display fake error messages stating that your computer in infected with spyware and other malicious software. It will rate major components of your system by given scores. They are usually very low. Once installed, Windows Express Help will prompt you to start your computer in protected mode to ensure that your computer is properly protected against possible attacks and malware. However, in reality it blocks programs on your computer randomly and states that they are infected or potentially harmful.Warning!Security alertName: taskmgr.exeLocation: C:WINDOWSSystem32Attempt to modify register key entries is detected. Register entries analysis is recommended.Deny or Enable Protection.Windows Express Help is a scam. It displays fake error messages and security alerts to make you think that your computer in infected. Then it prompts to pay for a full version of the program to clean up the computer. Do not buy. Instead, use our removal instructions below to remove Windows Express Help.

Renus 2008
Renus 2008 is a rogue anti-spyware application, fake spyware remover. This parasite is suspiciously similar to other notorious rogue anti-spyware applications, such as Real Antivirus and Antivirus XP Pro. So, we can assume that Renus 2008 is simply a copy of those noxious spyware removers. Usually, the system is infected with Renus2008 without user's knowledge or permission via Trojan application. These dangerous applications enter the system via security exploits, spam e-mails or fake online anti-virus scanners. Once installed and active, Renus 2008 performs fake system scan and generates fallacious alert messages or fake scan reports, informing that system is seriously infected. Victims of this rogue should know that all those infections were fabricated. For infections removal, user is advertised to buy a full copy of Renus 2008, because trial version has several limitations. The truth is that Renus 2008 only mimics real anti-spyware applications, so it is unable to detect or remove any kind of infections. Full version of Renus 2008 doesnât even exist. Instead of buy this worthless application, remove it from the system as soon as possible after first appearance.

Windows XP Restore
Windows XP Restore is a rogue computer optimization and defragmentation program that wants to scare you into thinking that your computer has some problems and issues. Windows XP Restore pretends to scan your hard drives and system memory for various errors. Then it states that you need to use the defragment tool to fix supposedly found errors. It fixes some errors for free and then prompts to pay for a full version of the program to fix other programs as well. Please do not fall victim to this rogue program and remove Windows XP Restore from your computer upon detection. Please use the removal instructions below. Windows XP Restore enters the system without user permission and in order to protect itself attempts to disable legit antimalware software found. Actually, it blocks nearly all programs on the computer. Just run a program several times and it will eventually work. Compromised computer becomes completely taken over by this fake program in the result of such actions and Windows XP Restore begins the campaign it was designed to. Win Defrag will be configured to launch at startup, so be sure it will greatly affect your computer by running fake scanners and pop-up ads or notifications that will annoy you.Overall, your computer will work slower. You will also see fake alerts from Windows taskbar. As you can see, Windows XP Restore is a total scam. Do not purchase it. If you have this rogue program on your computer please use the removal instructions below. You can remove Windows XP Restore manually but we strongly recommend to use an automatic removal tool given below.

Antivirus
Antivirus is a misleading security application that deliberately displays fake security alerts or reviews and reports false system security threats to convince you that your computer is badly infected with malware. This may sound a bit confusing, Antivirus â that's the name of the rogue program. It's not the most original name for a rogue program after all. The misleading application uses Windows OS design elements you make it look more reputable and reliable. Once installed, Antivirus will imitate system scan and reports false computer threats but won't remove them unless you purchase the program. However, please do not purchase this program and uninstall Antivirus from your PC as soon as possible. Removal delay may only worsen the situation because this parasite is able to download additional malware onto your computer. When running, Antivirus will impersonate Windows Security Center and state that your computer is unprotected. Please note, that the legitimate Security Center doesn't promote any anti-virus software; however the fake one promotes Antivirus malware. What is more, you will be taken to various misleading websites full of fake reviews. The rogue program modifies Windows Hosts file to trick you that those reviews are from well know and trusted websites including PCmag.com and zdnet.com. Obviously, in those reviews Antivirus rogue is described as top security program, best buy and etc. However, in reality it is just another scam design to steal money from not so experienced people. If you find that your computer is infected with this virus, please use the removal guide below to remove Antivirus manually for free.

Internet Security
Internet Security is a fake antivirus program that was designed by computer hackers in order to steal money from random computer users. The application generates security related warnings and pop up ads in order to scare computer users into believing that their systems are infected. The program uses Trojan viruses in order to get inside the system. Once there the program imitates being a reputable security tool. Unfortunately, this is far away from the truth.Internet Security imitates scanning your system with its bogus scanner and then warns about tons of infections supposedly detected on your machine. The program recommends deleting them with its full version. One more thing to mention is that Internet Security displays tons of fake alerts and security notifications warning that a certain application cannot be executed and similar things. These messages are completely fake and they are only displayed to make you believe that your system has some security issues. They should not be taken for granted just like the results of Internet Security scanner.Do not fall for this trick of cyber criminals. Remove Internet Security as soon as possible using a reputable antispyware program. If you have paid for the program, contact your credit card company and dispute the charges. Otherwise, your money will go straight to the computer hackers and you can forget about it. Make sure you upgrade your antimalware program before running a full system scan.

Windows Protection Suite
Windows Protection Suite is a misleading anti-virus application that uses false scan results and fake security alerts to make you think your computer is infected with spyware, Trojans and other malware. The rogue program provides exaggerated scan results and then suggests buying a full version of this fake program to remove non-existing system security threats. Windows Protection Suite is from the same family as Windows Security Suite, Malware Destructor 2009, Virus Shield 2009, Extra Antivirus, Virus Sweeper, Virus Doctor, Virus Melt. Windows Protection Suite is promoted through the use of Trojan viruses and fake online anti-malware scanners. The security threat can be also downloaded and installed manually from its homepage windowsprotectionsuite.com. Once installed, this parasite will be configured to scan your computer automatically each time you log on into Windows. WindowsProtection Suite will report a variety of infections and privacy issues ans state that you must purchase the program in order to fix those problems. What is more, it will constantly display legitimately looking security alerts from Windows task bar. The misleading program will also impersonate Windows Security center. It may display security warnings and notifications about unprotected computer and possible attacks from a remote machine. Fake notification from Windows task bar reads:"System Alertmalicious applications, which can contain trojans, were found on your PC and need to be immediately removed. Click here to remove these potentially harmful items using Windows Protection Suite"While running, WindowsProtectionSuite will dramatically decrease system performance. Likely it will delete system restore points and block all found security applications. To make things worse, Windows Protection Suite will hijack Internet browsers and search results. If you wind that your computer is infected with this bogus software, please use the manual removal guide below to remo...

Security Shield
Security Shield is a rogue anti-spyware program from the same family as System Tool and Security Tool. Once installed, it will supposedly scan your computer for spyware, adware, trojans and other malware. Of course, it will find numerous infections and then will prompt you to pay for a full version of Security Shield in order to remove non-existent infections. This fake security program will also display fake alerts and notifications stating that your computer in under attack or that your sensitive information can be stolen. This program is a scam. If your computer is infected with this malware then you should use our removal instructions below to remove Security Shield and any related malware either manually or with an automatic removal tool. While SecurityShield is running, it will block certain programs and display a fake error message. The fake message reads: Security Shield "cmd.exe" is infected with "Worm.Win32.Autorun.bnb". Do you want to register your copy and remove all threats now? Security Shield also hijacks Dekstop and Web browsers to further scare you into thinking that your computer is infected or has other problems, security issues. It may redirect you to misleading and malicious web sites and even display porn pop-ups on your screen. The fake alerts and notifications read: Security Shield Warning Spyware.IEMonster activity detected. This form of spyware attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other commonly used programs. Click here to immediately remove it with Security Shield. Security Shield Warning Intercepting malicious software that may violate your privacy and harm your computer has been detected. Click here to remove now with Security Shield. Security Shield Warning Some of the important system files on your PC were modified by malicious software. It may cause system crashes and data losses. Click here to prevent non-authoriz...

Internet Security 2010
Internet Security 2010 (also known as IS2010) is a rogue antivirus program. Please read the removal instructions and get rid of this fake program from your computer as soon as possible. InternetSecurity2010 is a clone of Advanced Virus Remover malware. If you take a closer look, you will see that both programs use the same graphical user interface. This rogue application is promoted through the user of Trojans. Most of the time, Trojans have to be manually installed and may come from various misleading websites, for example fake online anti-malware scanners. When running such media player processes as QuickTimePlayer.exe, AdvancedDVDPlayer.exe, tvp.exe, realplay.exe, windvd.exe, winamp.exe, setupwm.exe, LA.exe, PowerDVD.exe, mplayerc.exe, wmplayer.exe, Internet Security 2010 additionally displays many fake error messages, such as:Windows cant play the folowing media formats: AVI;WMV;AVS;FLV;MKV;MOV;3GP;MP4;MPG;MPEG;MP3;AAC;WAV;WMA;CDA;FLAC;M4A;MID. Update your video and sound codec to resolve this issue!Internet Security 2010 imitates a system scan and reports many false system security threats. Then it will redirect its victims to vs-codec-pro.net where it is asked to pay for a full version of the program to remove those security issues or infections. However, do not buy it - this is a scam. [Figure 1. Internet Security 2010 graphical user interface]When running, Internet Security 2010 will also display fake security alerts. Those alerts will state that IS2010 has found critical vulnerabilities on your computer. The rogue program displays these infections:Rogue:W32/XPAntivirus.gen!AdWare.Win32.ZwangiTrojan-Spy.HTML .Visafraud.aWorm:W32/AgentTrojan-PSW.W32/SteamNet-Worm.Win32.DipNet.dTr ojan-Dropper:W32/Trojan-DropperWorm:W32/Downadup.genTrojan-Downlaoder:W32 /Fakerean.gen!ANet-Worm.Win32.Mytob.tTrojan-Spy.Win32.Hookit.11Trojan-Cl icker.HTML.IFrame.gVirus:W32/Alman.bTrojan-Dropper.Win32.Agent.sdEmail-W orm.Win32NetSky.qriskware.Win32Ro...

Trojan.Agent
Trojan.Agent is not a threat in itself, it is a fake threat displayed by rogue anti-spyware programs. These programs use this and other scare tactics to get the user to buy the full version of the fake spyware removal programs.Programs related to Trojan.Agent should not be trusted under any circumstances and should be removed upon detection.

Ardamax Keylogger
Ardamax Keylogger is a commercial system surveillance tool that tracks user activity and records all keystrokes. It sends the log to a configurable e-mail address or uploads it to a predefined FTP server. Ardamax Keylogger is able to hide its running processes and therefore avoid a detection. The threat must be manually installed. It runs on every Windows startup.

PC MightyMax
PC MightyMax can be classified as fake and useless diagnostic tool, because it can be difficult to exit without purchasing the full version of this product. It seems that PC Mighty Max was design to periodically display pop-up windows and distracting alerts in order to scare users hopping that they will buy this worthless application.PC MightyMax runs automatically when computer starts, and there is no easy way how to change this behaviour. What is more, it has no setting to allow users to disable this function. Every few hours, PC MightyMax displays "CRITICAL ALERT" and "Alert!!!" pop-up windows that are mainly advertisements for the full version of the this software. These officious alerts can even make beeping noises decreasing user's ability to work with his computer. Summing-up, PC MightyMax may be considered as unwanted application which should be removed without consideration.

Smart Anti-Malware Protection
Smart Anti-Malware Protection is a rogue anti-spyware program that displays annoying and false security warnings to trick users into purchasing completely bogus security product. This rogue is from the same family as Antivirus Smart Protection and some other rogueware. Most of the time it's distributed through the use of Trojan horses, drive-by downloads and fake onine scanners. Scammers however, may use various social engineering methods to persuade social network users to install Smart Anti-Malware Protection. When the program is installed it will be configured to start automatically when Windows starts. While installing , Smart Anti-Malware Protection will create numerous harmless files on the infected computer. These fake files are then detected as infections when the rogue program scans the infected computer. The program will not remove them, though, until you purchase it or valid activation key. This is a scam as the files it detects are the files it created on your computer in the first place. Scan results are completely false. Do not trust this program and remove it from your computer as soon as possible.When Smart Anti-Malware Protection is running it will fake security alerts to further scare you into thinking you are infected. Some of the pop-up windows may look exactly like the legitimate Windows Security Center or system notifications. While Smart Anti-Malware Protection is running it will also display fake notifications from the task bar.System Alert Suspicious software which may be malicious has been detected on your PC. Click here to remove this threat immediately using Antivirus Smart Protection.System Alert Antivirus Smart Protection has detected potentially harmful software in your system. It is strongly recommended that you register Antivirus Smart Protection to remove all found threats immediately.System Alert Potentially harmful programs have been detected in you...

W32.Blaster.E.Worm
W32.Blaster.E.Worm is a worm that exploits the DCOM RPC vulnerability using TCP port 135. The worm targets only computers with Windows 2000 and Windows XP. It tries to download the Mslaugh.exe file into the System folder, and then execute it.

EoRezo
EoRezo is unwanted application that was included to the latest virus analysis report. Named as adware, it's installed without users' knowledge or consent and additionally set to create and drop eorezo.exe, SoftwareUpdateHP.exe and other files that should be uninstalled if you want to remove EoRezo from your computer. If left on machine, Win32/EoRezo starts initiating unwanted activity which stays unnoticed in most of the cases. Security experts report that this application has been found to produce various advertisements, collect and send spam letters from victim's email and do other stuf. In addition, it will also make some minor modifications helping this adware to start as soon as PC is rebooted. In order to remove EoRezo, use reputable anti-malware program after updating it to have all virus fixes.

Last Update:

Get the CISSP Prep Guide 2nd Edition!

Valuable Wireless Security Information!

Pass the CompTIA Security + Exam!

 

About    Bios    Contact    Partners    Privacy Statement