<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ThreatFire Research Blog &#187; Search Results  &#187;  label/Rogueware</title>
	<atom:link href="http://blog.threatfire.com/?s=label/Rogueware&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Thu, 12 Nov 2009 20:45:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ATTENTION! If your computer is struck by the spyware, you could suffer</title>
		<link>http://blog.threatfire.com/2008/11/attention-if-your-computer-is-struck-by-the-spyware-you-could-suffer.html</link>
		<comments>http://blog.threatfire.com/2008/11/attention-if-your-computer-is-struck-by-the-spyware-you-could-suffer.html#comments</comments>
		<pubDate>Tue, 18 Nov 2008 00:12:00 +0000</pubDate>
		<dc:creator>ThreatFire Blogger</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogueware]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/11/attention-if-your-computer-is-struck-by-the-spyware-you-could-suffer/</guid>
		<description><![CDATA[&#8230;from all sorts of bad things. We know.

However, you may be seeing this mis-spelled message, which has changed a little bit over the past few months:&#8220;ATTENTION! If your computer is struck by the spyware, you could suffer data loss, erratic PC behaviour, PC freezes and creahes.&#8221;
By the spyware? Creahes? Who writes this stuff?
&#8220;Detect and remove [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;from all sorts of bad things. We know.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SSIKVyAou6I/AAAAAAAAAn4/uCniO4nsap0/s1600-h/ATTENTION%21.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 46px;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SSIKVyAou6I/AAAAAAAAAn4/uCniO4nsap0/s200/ATTENTION%21.png" alt="" id="BLOGGER_PHOTO_ID_5269785883294874530" border="0" /></a></p>
<p>However, you may be seeing this mis-spelled message, which has changed a little bit over the past few months:<br />&#8220;ATTENTION! If your computer is struck by the spyware, you could suffer data loss, erratic PC behaviour, PC freezes and creahes.&#8221;</p>
<p>By the spyware? Creahes? Who writes this stuff?</p>
<p>&#8220;Detect and remove viruses before they damage your computer!<br />Antivirus 2009 will perform a 100% FREE and quick scan of your computer for Viruses, Spyware and Adware.<br />Do you want to install Antivirus 2009 to scan your computer for malware now? (Recommended)&#8221;</p>
<p>Please be wary of this sort of scheme through the end of the year. A number of banner ads on very popular web sites have been redirecting users to sites serving up this garbage. This <a href="http://blog.threatfire.com/search/label/Rogueware" target="_blank">rogueware</a> &#8220;Antivirus 2009&#8243; ad in particular will re-direct your browser to a web site using only javascript to mis-represent a common online malware scan of your windows system. As we&#8217;ve <a href="http://blog.threatfire.com/2008/08/you-have-security-problem.html" target="_blank">discussed before</a> and at <a href="http://www.virusbtn.com/pdf/conference_slides/2008/KurtBaumgartner-VB2008.odp" target="_blank">Virus Bulletin</a> (slides on <a href="http://www.slideshare.net/kurtbaumgartner/k-baumgartner-recent-rogueware-presentation/" target="_blank">flash</a> here), this stuff will attempt to shock you with a number of malware detections that are not really present on your computer, coercing you to pay for phony AV software. They detect the make-believe &#8220;Spyware.IEMonster.b&#8221;, &#8220;Zlob.PornAdvertizer.Xplisit&#8221;, and &#8220;Trojan.Infostealer.Banker.s&#8221;, made-up names which unsurprisingly do not change:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SSIKOj5RIUI/AAAAAAAAAnw/_pWfAJx9QEA/s1600-h/AV2009.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 158px;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SSIKOj5RIUI/AAAAAAAAAnw/_pWfAJx9QEA/s200/AV2009.png" alt="" id="BLOGGER_PHOTO_ID_5269785759246786882" border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/11/attention-if-your-computer-is-struck-by-the-spyware-you-could-suffer.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
