ThreatFire Research Blog Home
 
 
« PC Tools at Virus Bulletin 2009
Your Computer is Infected!, Probably Because of that Bredolab Attachment »

Total Security and pav.exe

Previous posts showed spam-based scams attempting to deliver a payload named “pav.exe” onto your system. The scam is continuing with the title “Total Security” for the familiar scareware messages. Be aware that there is a legitimate security suite that includes those words in its name, but this scam is not that legitimate package. You can recognize the fake scan with phony detections here:

Phony scan offering and immediate scan requirement here:
“Warning!!! Your system requires immediate anti viruses scan! Total Security can perform fast and free virus and malicious software scan of your computer .”

Full phony detection message here:
“Harmful and malicious software detected. Such programs may damage your computer and steal your private information. Online Security Scanner requires Total Security components to repair your computer. Please click OK to download and install Total Security tool.”

Today and yesterday’s most active domains/ip addresses included:
88.198.120.177
antispyware-scanner2 .com
antispyware-scanner5 .com
antivirus-online-scan7 .com
best-antivirus9 .com
live-virus-scanner3 .com
online-best-scanv3 .com
premium-antispy-scanv3 .com
premium-antispy-scanv7 .com
professionalcomputerscanv2 .com
safeonlinescannerv4 .com
safeonlinescanv4 .com
secure-spyware-scannerv3 .com

91.212.127.200
antispyware-scanner2 .com
antispyware-scanner5 .com
antivirus-online-scan7 .com
best-antivirus9 .com
live-virus-scanner3 .com
professionalcomputerscanv2 .com
safeonlinescannerv4 .com
safeonlinescanv4 .com

88.198.81.153
antivirus-scannerv17 .com
best-security-scanv8 .com
bestantispywarescanv4 .com
professionalspywarescanv8 .com
professionalvirusscanv3 .com

78.46.251.43
antivirus-online-scan5 .com
antivirus-scannerv12 .com
antivirus-scannerv15 .com
getyourantivirusv3 .com

83.133.126.201
antivirus-scannerv17.com
bestantispywarescanv4.com
professionalspywarescanv8.com
professionalvirusscanv3.com
protectedsecurityaudit.cn

ThreatFire preventions for this scareware/rogueware payload continue to be on the rise. Before installing any software, be sure to inform yourself by looking into opinions and reviews of legitimate products.

This entry was posted on Monday, August 31st, 2009 at 12:33 pm and is filed under FakeAlert, Rogueware. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).