<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TechJaws.com &#187; Fake Antivirus</title>
	<atom:link href="http://www.techjaws.com/category/security/misleading-applications-security-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techjaws.com</link>
	<description></description>
	<lastBuildDate>Thu, 29 Jul 2010 16:10:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security Tool Installs as a Firefox and Flash Update</title>
		<link>http://www.techjaws.com/security-tool-installs-as-a-firefox-and-flash-update/</link>
		<comments>http://www.techjaws.com/security-tool-installs-as-a-firefox-and-flash-update/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 14:37:47 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Fake Adobe Flash Player]]></category>
		<category><![CDATA[Fake Firefox Just Updated]]></category>
		<category><![CDATA[Firefox Malicious Update]]></category>
		<category><![CDATA[How to Remove Security Tool Virus]]></category>
		<category><![CDATA[Security Tool Virus Removal]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8705</guid>
		<description><![CDATA[The pesky Security Tool Virus is back again, but this time, the rogue distributors are using a different tactic to get users to install this malicious and fake antivirus program. The old trick was false and exaggerated scans that would make a user believe that their system is infected. The playing field has changed as [...]]]></description>
			<content:encoded><![CDATA[<p>The pesky <strong>Security Tool Virus</strong> is back again, but this time, the rogue distributors are using a different tactic to get users to install this malicious and <strong>fake antivirus program</strong>.</p>
<p>The old trick was false and exaggerated scans that would make a user believe that their system is infected. The playing field has changed as these criminals are now using a fake Firefox &#8220;<strong>Just Updated</strong>&#8221; page. This is the page that loads immediately after an Firefox update.  The page shows a message that tells the user that they need to update their <strong>Adobe Flash Player</strong>.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/firefox-update-security-tool.png"><img class="alignnone size-full wp-image-8706" style="border: 0pt none; margin: 0px;" title="firefox-update-security-tool" src="http://www.techjaws.com/wp-content/uploads/2010/07/firefox-update-security-tool.png" alt="Fake Firefox Update Installs Security Tool Virus" width="600" height="446" /></a></p>
<p>Once a user is on the “<strong>Just Updated</strong>” page, a download dialog box will pop-up automatically without the user clicking anything on the page. If the user clicks “Save File” the rogue antivirus program will be installed. This rogue program will wreck havoc on a users system and cause the system to be unusable.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/security-tool-installer.png"><img class="alignnone size-full wp-image-8707" style="border: 0pt none; margin: 0px;" title="security-tool-installer" src="http://www.techjaws.com/wp-content/uploads/2010/07/security-tool-installer.png" alt="Security Tool Virus" width="403" height="178" /></a></p>
<p><strong><span style="text-decoration: underline;">How to remove Security Tool Virus</span></strong></p>
<p><strong>Manually<span style="text-decoration: underline;"><br />
</span></strong></p>
<ol>
<li>Stop Security Tool Processes: [random numbers].exe</li>
<li>Remove Security Tool Files</li>
<li>C:\Documents and Settings\All Users\Application      Data\[random numbers]\</li>
<li>C:\Documents and Settings\All Users\Application      Data\[random numbers]\[random numbers].exe</li>
<li>Remove Security Tool Registry Keys</li>
</ol>
<p>*HKEY_CURRENT_USER\Software\Security Tool<br />
*HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Tool</p>
<ol>
<li>Remove Security Tool Startup Entry: [random      numbers].exe</li>
</ol>
<p><strong>Automatically</strong></p>
<ul>
<li>You can also download <a title="Malware Removal Software" href="http://www.malwarebytes.org/" target="_blank">MalwareBytes Anti-Malware</a> to remove Security Tool Virus.</li>
<li>F-Secure has already updated their AV product to block and remove Security Tool Virus. They offer a 30 day free trial of <a title="Remove Security Tool Virus" href="http://www.f-secure.com/en_EMEA/downloads/" target="_blank">Anti-Virus 2010</a>.</li>
</ul>
<p>Read more removal instructions and comments <a title="How to Remove Security Tool Virus" href="../how-to-remove-security-tool/">here</a>.</p>
<div style='display:none' id="post-refEl-8705"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/security-tool-installs-as-a-firefox-and-flash-update/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Beware of Antispymv.com a Malicious Website</title>
		<link>http://www.techjaws.com/beware-of-antispymv-com-a-malicious-website/</link>
		<comments>http://www.techjaws.com/beware-of-antispymv-com-a-malicious-website/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 16:58:40 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Scams & Hoaxes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivir Solution Pro Removal]]></category>
		<category><![CDATA[Browser Hijacker]]></category>
		<category><![CDATA[How to Remove Antivir Solution Pro]]></category>
		<category><![CDATA[Malicious Websites]]></category>
		<category><![CDATA[Misleading Application]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8616</guid>
		<description><![CDATA[Antispymv.com is a browser hijacker that distributes Antivir Solution Pro program and other fake antivirus solutions. This rogue software spreads from a Trojan and is installed automatically without user’s knowledge and consent. Type: Misleading Application / Browser Hijacker Publisher: Antispymv.com Risk Impact: Medium Systems Affected: Windows 2000, Windows Server 2003, Windows Vista, Windows XP Behavior: [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Antispymv.com</strong> is a <strong>browser hijacker</strong> that distributes <strong>Antivir Solution Pro</strong> program and other fake antivirus solutions. This rogue software spreads from a Trojan and is installed automatically without user’s knowledge and consent.</p>
<p><strong>Type: </strong>Misleading Application / Browser Hijacker<br />
<strong>Publisher</strong>: Antispymv.com<br />
<strong>Risk Impact: </strong>Medium<br />
<strong>Systems Affected: </strong>Windows 2000, Windows Server 2003, Windows Vista, Windows XP<br />
<strong>Behavior: </strong>Antivir Solution Pro is a misleading application that may give exaggerated reports of threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/antivirus-suite.png"><img class="alignnone size-full wp-image-8618" style="border: 0pt none; margin: 0px;" title="antivirus-suite" src="http://www.techjaws.com/wp-content/uploads/2010/07/antivirus-suite.png" alt="Antivir Solution Pro Removal" width="599" height="454" /></a></p>
<p><strong>How to remove Antivir Solution Pro:</strong></p>
<p>Download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’ Anti-Malware</a> to remove this software.</p>
<p><strong>How to manually remove Antivir Solution Pro registry values:</strong></p>
<p>Note: The manual removal of files and registries should be performed by experienced users.</p>
<ul>
<li>HKEY_CURRENT_USER\Software\AvSuite</li>
<li>HKEY_LOCAL_MACHINE\Software\AvSuite</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet      Explorer\Download “RunInvalidSignatures” =”1″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet      Settings “ProxyOverride” = “”</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet      Settings “ProxyServer” = “http=127.0.0.1:5555″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations      “LowRiskFileTypes” = “.exe”</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments      “SaveZoneInformation” = “1″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run      “{random string}”</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run      “{random string}”</li>
</ul>
<p><strong>Other malicious files:</strong></p>
<ul>
<li>%Documents and Settings%\[UserName]\Local      Settings\Application Data\{random string}\{random string}.exe</li>
</ul>
<p>See more rogue software removal instructions <a title="Fake Antivirus Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<p>If you have the <a title="WOT - Web of Trust" href="http://www.mywot.com/" target="_blank">WOT add-on</a> installed for Firefox or IE, you will now get a warning for this malicious website.</p>
<p><span style="text-decoration: underline;"><strong>Related Articles</strong></span><br />
<a title="How to Remove Antivirus GT" href="../how-to-remove-antivirus-gt/">How to Remove Antivirus GT</a><br />
<a title="How to Remove MedicCop Rogue AntiSpyware" href="../how-to-remove-mediccop-rogue-antispyware/">How to Remove MedicCop Rogue AntiSpyware</a><br />
<a title="Beware of this Fake Antivirus Program AV Security Suite" href="../beware-of-this-fake-antivirus-program-av-security-suite/">Beware of this Fake Antivirus Program AV Security Suite</a></p>
<div style='display:none' id="post-refEl-8616"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/beware-of-antispymv-com-a-malicious-website/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivirus GT</title>
		<link>http://www.techjaws.com/how-to-remove-antivirus-gt/</link>
		<comments>http://www.techjaws.com/how-to-remove-antivirus-gt/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 14:51:28 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus GT]]></category>
		<category><![CDATA[Antivirus GT Manual Removal]]></category>
		<category><![CDATA[How to remove Antivirus GT]]></category>
		<category><![CDATA[How to Remove Rogue Software]]></category>
		<category><![CDATA[Misleading Application]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8602</guid>
		<description><![CDATA[Antivirus GT is a rogue anti-virus program. Graffiti-Blogger.com is the site that promotes Antivirus GT program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads Antivirus GT and runs a scan, the program reports false scan alerts. The user is then prompted [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Antivirus GT</strong> is a <strong>rogue anti-virus</strong> program. Graffiti-Blogger.com is the site that promotes Antivirus  GT program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads Antivirus GT and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the application in order to remove the threats.</p>
<p><strong>Type: </strong>Misleading Application<br />
<strong>Name: </strong>Antivirus GT<br />
<strong>Website</strong>: Graffiti-Blogger.com<br />
<strong>Risk Impact: </strong>Medium<br />
<strong>Systems Affected: </strong>Windows 2000, Windows Server 2003, Windows Vista, Windows XP<br />
<strong>Behavior: </strong>Antivirus GT is a misleading application that may give exaggerated reports of threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/antivirus-gt.png"><img class="alignnone size-full wp-image-8603" style="border: 1px solid black; margin: 0px;" title="antivirus-gt" src="http://www.techjaws.com/wp-content/uploads/2010/07/antivirus-gt.png" alt="How to remove Antivirus GT" width="600" height="291" /></a></p>
<p><span style="text-decoration: underline;"><strong>How to Remove Antivirus GT</strong></span></p>
<p>Download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’ Anti-Malware</a> to remove this software.</p>
<p><strong>Antivirus GT Manual Removal:</strong></p>
<p>Note: The manual removal of files and registries should be performed by experienced users.</p>
<p><strong>Antivirus GT registry values:</strong></p>
<p>HKEY_CURRENT_USER\Software\EVA246<br />
HKEY_CLASSES_ROOT\CLSID\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AVGT”<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “WinNT-EVI 12.03.2010″</p>
<p><strong>Antivirus GT DLLs:</strong></p>
<p>UpdateExplorer.dll</p>
<p><strong>Other malicious Antivirus GT files:</strong></p>
<p>c:\Documents and Settings\All Users\Start Menu\AVGT<br />
c:\Documents and Settings\All Users\Start Menu\AVG\Antivirus GT.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AVG\Uninstall.lnk<br />
c:\Program Files\AVGT<br />
c:\Program Files\AVGT\Antivirus GT.exe<br />
c:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb<br />
c:\WINDOWS\system32\UpdateExplorer.dll<br />
%UserProfile%\Desktop\Antivirus GT.lnk</p>
<p>See more rogue software removal instructions <a title="Fake Antivirus  Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<p>If you have the <a title="WOT - Web of Trust" href="http://www.mywot.com/" target="_blank">WOT add-on</a> installed for Firefox or IE, you will now get a warning for this malicious website.</p>
<p><span style="text-decoration: underline;"><strong>Related Articles</strong></span><br />
<a title="How to Remove MedicCop Rogue AntiSpyware" rel="bookmark" href="../how-to-remove-mediccop-rogue-antispyware/">How to  Remove MedicCop Rogue AntiSpyware</a><br />
<a title="How to Remove Antivir Solution Pro" rel="bookmark" href="../how-to-remove-antivir-solution-pro/">How to Remove  Antivir Solution Pro</a><br />
<a title="Beware of this Fake Antivirus Program AV Security  Suite" rel="bookmark" href="../beware-of-this-fake-antivirus-program-av-security-suite/">Beware of this Fake Antivirus Program AV Security Suite</a></p>
<div style='display:none' id="post-refEl-8602"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/how-to-remove-antivirus-gt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove MedicCop Rogue AntiSpyware</title>
		<link>http://www.techjaws.com/how-to-remove-mediccop-rogue-antispyware/</link>
		<comments>http://www.techjaws.com/how-to-remove-mediccop-rogue-antispyware/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 17:11:24 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Fake Security Program]]></category>
		<category><![CDATA[Fake Software]]></category>
		<category><![CDATA[How to Remove MedicCop]]></category>
		<category><![CDATA[MedicCop Removal]]></category>
		<category><![CDATA[Rogue AntiSpyware]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8569</guid>
		<description><![CDATA[MedicCop is a rogue Anti-Spyware program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads MedicCop and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the application in order [...]]]></description>
			<content:encoded><![CDATA[<p><strong>MedicCop</strong> is a rogue Anti-Spyware program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads MedicCop and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the application in order to remove the threats.</p>
<p><strong>Type: </strong>Misleading Application<br />
<strong>Name: </strong>MedicCop<br />
<strong>Risk Impact: </strong>Medium<br />
<strong>Systems Affected: </strong>Windows 2000, Windows Server 2003, Windows Vista, Windows XP<br />
<strong>Behavior: </strong>MedicCop is a misleading application that may give exaggerated reports of threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/mediccop.jpg"><img class="alignnone size-full wp-image-8570" style="border: 0pt none; margin: 0px;" title="How to remove MedicCop" src="http://www.techjaws.com/wp-content/uploads/2010/07/mediccop.jpg" alt="MedicCop Removal" width="499" height="318" /></a></p>
<p><strong>How to remove MedicCop:</strong></p>
<p>Download and install<strong> </strong><a href="http://www.howtogeek.com/howto/9283/superantispyware-portable-is-the-must-have-spyware-removal-tool-you-need/">SUPERAntiSpyware</a> and <a href="http://www.malwarebytes.org/">Malwarebytes Anti-Malware</a>. Both security programs come with free versions.</p>
<p>I recommend that you run multiple passes of <a href="http://www.howtogeek.com/howto/9283/superantispyware-portable-is-the-must-have-spyware-removal-tool-you-need/">SUPERAntiSpyware</a> and <a href="http://www.malwarebytes.org/">Malwarebytes Anti-Malware</a>.</p>
<p>It’s important that you keep your <span style="color: #000000;">security programs</span> up to date. I highly recommend downloading the <a title="Web of Trust" href="http://www.mywot.com/" target="_blank">WOT (Web of Trust)</a> add-on for IE and/or Firefox. The WOT add-on warns you about risky sites  before you click.</p>
<p><span style="text-decoration: underline;"><strong>Related Articles</strong></span><br />
<a title="How to Remove Antivir Solution Pro" rel="bookmark" href="../how-to-remove-antivir-solution-pro/">How to Remove  Antivir Solution Pro</a><br />
<a title="Beware of this Fake Antivirus Program AV Security  Suite" rel="bookmark" href="../beware-of-this-fake-antivirus-program-av-security-suite/">Beware of this Fake Antivirus Program AV Security Suite</a></p>
<div style='display:none' id="post-refEl-8569"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/how-to-remove-mediccop-rogue-antispyware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivir Solution Pro</title>
		<link>http://www.techjaws.com/how-to-remove-antivir-solution-pro/</link>
		<comments>http://www.techjaws.com/how-to-remove-antivir-solution-pro/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 20:28:04 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivir Solution Pro]]></category>
		<category><![CDATA[Antivir Solution Pro Removal]]></category>
		<category><![CDATA[How to Remove Antivir Solution Pro]]></category>
		<category><![CDATA[Remove Antivir Pro]]></category>
		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8494</guid>
		<description><![CDATA[Antivir Solution Pro is rogue anti-spyware program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads Antivir Solution Pro and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Antivir Solution Pro</strong> is <strong>rogue anti-spyware</strong> program. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads <strong>Antivir Solution Pro</strong> and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the application in order to remove the threats.</p>
<p><strong>Type: </strong>Misleading Application<br />
<strong>Name: </strong>Antivir Solution Pro<br />
<strong>Risk Impact: </strong>Medium<br />
<strong>Systems Affected: </strong>Windows 2000, Windows Server 2003, Windows Vista, Windows XP<br />
<strong>Behavior: </strong>Antivir Solution Pro is a misleading application that may give exaggerated reports of threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/antivir-solution.jpg"><img class="alignnone size-full wp-image-8495" style="border: 0pt none; margin: 2px 3px;" title="antivir-solution" src="http://www.techjaws.com/wp-content/uploads/2010/07/antivir-solution.jpg" alt="Rogue Antispyware" width="519" height="462" /></a></p>
<p><strong>How to remove Antivir Solution Pro:</strong></p>
<p>Download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’ Anti-Malware</a> to remove this software.</p>
<p><strong>How to manually remove Antivir Solution Pro registry values:</strong></p>
<p>Note: The manual removal of files and registries should be performed by experienced users.</p>
<ul>
<li>HKEY_CURRENT_USER\Software\AvSuite</li>
<li>HKEY_LOCAL_MACHINE\Software\AvSuite</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” =”1″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “{random string}”</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “{random string}”</li>
</ul>
<p><strong>Other malicious files:</strong></p>
<ul>
<li>%Documents and Settings%\[UserName]\Local Settings\Application Data\{random string}\{random string}.exe</li>
</ul>
<p>See more rogue software removal instructions <a title="Fake Antivirus Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<div style='display:none' id="post-refEl-8494"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/how-to-remove-antivir-solution-pro/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Beware of this Fake Antivirus Program AV Security Suite</title>
		<link>http://www.techjaws.com/beware-of-this-fake-antivirus-program-av-security-suite/</link>
		<comments>http://www.techjaws.com/beware-of-this-fake-antivirus-program-av-security-suite/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 17:09:13 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AV Security Suite Removal]]></category>
		<category><![CDATA[AVSecuritySuite]]></category>
		<category><![CDATA[How to Remove AV Security Suite]]></category>
		<category><![CDATA[Misleading Application]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8443</guid>
		<description><![CDATA[AV Security Suite is a Fake Antivirus application. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads AV Security Suite and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of [...]]]></description>
			<content:encoded><![CDATA[<p><strong>AV Security Suite</strong> is a <strong>Fake Antivirus</strong> application. This security risk can be downloaded by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads AV Security Suite and runs a scan, the program reports false scan alerts. The user is then prompted to pay for a full license of the application in order to remove the threats.</p>
<p><strong>Type: </strong>Misleading Application<br />
<strong>Infection Length: </strong>286,464 bytes<br />
<strong>Name: </strong>AV Security Suite<br />
<strong>Risk Impact: </strong>Medium<br />
<strong>Systems Affected: </strong>Windows 2000, Windows Server 2003, Windows Vista, Windows XP<br />
<strong>Behavior: </strong>AVSecuritySuite is a misleading application that may give exaggerated reports of threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/07/av-security-suite.jpg"><img class="alignnone size-full wp-image-8444" style="border: 0pt none; margin: 0px;" title="av-security-suite" src="http://www.techjaws.com/wp-content/uploads/2010/07/av-security-suite.jpg" alt="AV Security Suite Removal" width="540" height="410" /></a></p>
<p><span style="text-decoration: underline;"><strong>Installation</strong></span></p>
<p>When the program is executed, it creates the following file:<br />
%UserProfile%\Local Settings\Application Data\[FIRST SET OF RANDOM CHARACTERS]\[SECOND SET OF RANDOM CHARACTERS]tssd.exe</p>
<p>Next, the program creates the following registry entries so that it executes whenever Windows starts:</p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;[EIGHT      RANDOM CHARACTERS]&#8221; = &#8220;%UserProfile%\Local Settings\Application      Data\[FIRST SET OF RANDOM CHARACTERS]\[SECOND SET OF RANDOM CHARACTERS]tssd.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;[EIGHT      RANDOM CHARACTERS]&#8221; = &#8220;%UserProfile%\Local Settings\Application      Data\[FIRST SET OF RANDOM CHARACTERS]\[SECOND SET OF RANDOM      CHARACTERS]tssd.exe&#8221;</li>
</ul>
<p>It also modifies the following registry entries to lower Internet Explorer security settings:</p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet      Explorer\Download\&#8221;CheckExeSignatures&#8221; = &#8220;no&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet      Explorer\Download\&#8221;RunInvalidSignatures&#8221; = &#8220;1&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet      Explorer\PhishingFilter\&#8221;EnabledV8&#8243; = &#8220;0&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet      Explorer\PhishingFilter\&#8221;Enabled&#8221; = &#8220;0&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\&#8221;SaveZoneInformation&#8221;      = &#8220;1&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\&#8221;LowRiskFileTypes&#8221;      = &#8220;.exe&#8221;</li>
</ul>
<p>It also creates the following registry subkeys:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\AVSuitE</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\avSofT</li>
<li>HKEY_CURRENT_USER\Software\avSofT</li>
</ul>
<p><span style="text-decoration: underline;"><strong>How to Remove </strong></span><strong><span style="text-decoration: underline;">AV Security Suite</span><br />
</strong>The following instructions pertain to all current and recent Symantec Antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.</p>
<ol>
<li>Disable System Restore (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to the registry.</li>
</ol>
<p>For specific details on each of these steps, read the following <a href="http://www.symantec.com/norton/security_response/writeup.jsp?docid=2010-070507-2842-99&amp;tabid=3" target="_blank">instructions</a>.</p>
<p>if you do not have Norton Antivirus, you can download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’ Anti-Malware</a> to remove this software.</p>
<p>See more fake antivirus removal instructions <a title="Fake Antivirus  Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<div style='display:none' id="post-refEl-8443"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/beware-of-this-fake-antivirus-program-av-security-suite/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to Remove Internet Security 2010 Rogue Software</title>
		<link>http://www.techjaws.com/how-to-remove-internet-security-2010-rogue-software/</link>
		<comments>http://www.techjaws.com/how-to-remove-internet-security-2010-rogue-software/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 16:19:19 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[How to Remove Rogue Software]]></category>
		<category><![CDATA[Internet Security 2010]]></category>
		<category><![CDATA[Internet Security 2010 Removal]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Rogue Software Removal]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8229</guid>
		<description><![CDATA[Internet Security 2010 is a rogue (fake) internet security suit that gives false reports of threats on the computer. Once a user downloads this application, they’re prompted to purchase the full license in order to remove the false infection. Name: Internet Security 2010 Publisher: Internet Security 2010 Website: defendvirus.com Risk Impact: Medium Systems Affected: Windows [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Internet Security 2010</strong> is a rogue (fake) internet security suit that gives false reports of threats on the computer. Once a user downloads this application, they’re prompted to purchase the full license in order to remove the false infection.</p>
<p><strong>Name</strong>: Internet Security 2010<br />
<strong>Publisher</strong>: Internet Security 2010<br />
<strong>Website</strong>: defendvirus.com<br />
<strong>Risk Impact</strong>: Medium<br />
<strong>Systems Affected</strong>: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/06/is-2010.png"><img class="alignnone size-full wp-image-8230" style="border: 0pt none; margin: 0px;" title="is-2010" src="http://www.techjaws.com/wp-content/uploads/2010/06/is-2010.png" alt="How to Remove Internet Security 2010" width="602" height="454" /></a></p>
<p><strong>How to Remove </strong><strong>Internet Security 2010</strong></p>
<ol>
<li>Disable System Restore      (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to      the registry.</li>
</ol>
<p>You can download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’ Anti-Malware</a> to remove this software.</p>
<p>See more <strong>fake antivirus removal</strong> instructions <a title="Fake Antivirus Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<p><strong><span style="text-decoration: underline;">Related Links</span></strong></p>
<p><a title="Removing Rogue Fake Antivirus" href="../removing-rogue-fake-antivirus/">Removing Rogue Fake Antivirus</a><br />
<a title="How to Remove and Avoid Rogue Applications" href="../how-to-remove-and-avoid-rogue-applications/">How to Remove and Avoid Rogue Applications</a><br />
<a title="Rogue Software Rising at an Alarming Rate" href="../rogue-software-rising-at-an-alarming-rate/">Rogue Software Rising at an Alarming Rate</a></p>
<div style='display:none' id="post-refEl-8229"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/how-to-remove-internet-security-2010-rogue-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>FBI File Charges Against Scareware Authors</title>
		<link>http://www.techjaws.com/fbi-file-charges-against-scareware-authors/</link>
		<comments>http://www.techjaws.com/fbi-file-charges-against-scareware-authors/#comments</comments>
		<pubDate>Mon, 31 May 2010 13:39:16 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Fake Antivirus Removal]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[How to Remove Scareware]]></category>
		<category><![CDATA[Removing Rogue Software]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8195</guid>
		<description><![CDATA[Three men who made more than $100 million selling scareware have been charged by the FBI. They sold their fake antivirus programs in over 60 countries. The programs they sold that we published articles about are;  &#8221;Malware Alarm&#8220;, &#8220;Antivirus 2008&#8221; and &#8220;VirusRemover 2008&#8220;. Scareware has been on the rise since 2008 and it continues to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techjaws.com/wp-content/uploads/2010/05/scareware-fake-av.png"><img class="alignleft size-full wp-image-8198" style="border: 0pt none; margin: 2px 3px;" title="scareware-fake-av" src="http://www.techjaws.com/wp-content/uploads/2010/05/scareware-fake-av.png" alt="Scareware" width="203" height="203" /></a>Three men who made more than $100 million selling <strong>scareware</strong> have been charged by the FBI. They sold their fake antivirus programs in over 60 countries. The programs they sold that we published articles about are;  &#8221;<strong>Malware Alarm</strong>&#8220;, &#8220;<strong>Antivirus 2008</strong>&#8221; and &#8220;<strong>VirusRemover 2008</strong>&#8220;.</p>
<p>Scareware has been on the rise since 2008 and it continues to be the bread winner amongst scams. Scareware tricks users into thinking their computers are infected with viruses and or malware, and in order to remove the infection, a user must purchase the products license. In most cases, the victims visit particular websites and they are then urged to purchase scareware products such as; anti-spyware and antivirus products.</p>
<p>Such fraud was essentially outlawed at the end of 2008, when the Federal Trade Commission (FTC) got a US court to prevent two manufacturers of scareware from continuing to sell their products. The three men now facing charges did business from the US and the Ukraine via such companies as &#8220;Byte Hosting Internet Services&#8221; and &#8220;Innovative Marketing&#8221;.</p>
<p><strong>Facts</strong>: 15 percent of all malware is now scareware and that this percentage is still rising.</p>
<p><span style="text-decoration: underline;"><strong>Related Articles</strong></span></p>
<p><a title="Removing Rogue Fake Antivirus" href="../removing-rogue-fake-antivirus/">Removing Rogue Fake Antivirus</a><br />
<a title="How to Remove and Avoid Rogue Applications" href="../how-to-remove-and-avoid-rogue-applications/">How to Remove and Avoid Rogue Applications</a><br />
<a title="Rogue Software Rising at an Alarming Rate" href="../rogue-software-rising-at-an-alarming-rate/">Rogue Software Rising at an Alarming Rate</a><br />
<a title="Misleading Applications Rising at an Alarming  Rate" href="../misleading-applications-rising-at-an-alarming-rate/">Misleading Applications Rising at an Alarming Rate</a></p>
<p>The FBI and FTC may never stop the distribution of scareware all together, but charging these three men is a step in the right direction.</p>
<div style='display:none' id="post-refEl-8195"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/fbi-file-charges-against-scareware-authors/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Removing Rogue Fake Antivirus</title>
		<link>http://www.techjaws.com/removing-rogue-fake-antivirus/</link>
		<comments>http://www.techjaws.com/removing-rogue-fake-antivirus/#comments</comments>
		<pubDate>Mon, 17 May 2010 18:03:31 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spyware Removal]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[How to Remove Malware]]></category>
		<category><![CDATA[How to Remove Rogue Software]]></category>
		<category><![CDATA[Remove Fake Antivirus]]></category>
		<category><![CDATA[Security Tool Virus Removal]]></category>
		<category><![CDATA[Virus removal]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=8071</guid>
		<description><![CDATA[Rogue Fake Antivirus are distributed through websites that simulate virus scans. When a user downloads a Fake Antivirus program and runs a scan, the program reports false scan alerts. This rogue software tries to fool the user in purchasing the full license in order to remove the false threats. Unfortunately, these Fake Antivirus programs do [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.techjaws.com/wp-content/uploads/2010/05/rogue-programs1.png"><img class="alignleft size-full wp-image-8076" style="border: 0pt none; margin: 2px 3px;" title="rogue-programs" src="http://www.techjaws.com/wp-content/uploads/2010/05/rogue-programs1.png" alt="How to Remove Rogue Programs" width="260" height="192" /></a>Rogue Fake Antivirus</strong> are distributed through websites that  simulate virus scans. When a user downloads a <strong>Fake Antivirus</strong> program and runs a scan, the program  reports false scan alerts. This rogue software tries to fool the user in  purchasing the full license in order to remove the false threats. Unfortunately, these Fake Antivirus programs do more harm to your computer and are tough to remove.</p>
<p>There are a couple of ways to rid these <strong>Rogue Fake Antivirus Programs</strong>, but I am going to share a step by step approach that will remove a majority of these Fake Antivirus programs. If you follow the steps below, you should be able to clean your computer from most infections, including most Malware and Spyware.</p>
<p><span style="text-decoration: underline;"><strong>Steps to Remove Fake Antivirus Software</strong></span>:</p>
<ol>
<li>Download the free version of <a href="http://www.howtogeek.com/howto/9283/superantispyware-portable-is-the-must-have-spyware-removal-tool-you-need/">SUPERAntiSpyware</a> to remove Spyware left behind from Rogue Fake Antivirus programs.</li>
<li>Launch SUPERAntiSpyware and run a full system scan.</li>
<li>If you are still experiencing issues, try rebooting your PC in Safe Mode with networking (use F8 right before Windows starts to load).</li>
<li>Launch SUPERAntiSpyware and run a full system scan while your computer is in Safe Mode.</li>
<li>If that doesn’t work, download and install <a href="http://www.malwarebytes.org/">MalwareBytes</a> and run it, doing a full system scan.</li>
<li>Reboot your computer and run a full scan using your Antivirus application (I recommend <a title="Microsoft Security Essentials Update" href="../microsoft-security-essentials-update/">Microsoft Security Essentials</a>).</li>
<li>Your PC should be disinfected and running smoothly.</li>
</ol>
<p>I recommend that you run multiple passes of <a href="http://www.howtogeek.com/howto/9283/superantispyware-portable-is-the-must-have-spyware-removal-tool-you-need/">SUPERAntiSpyware</a> and <a href="http://www.malwarebytes.org/">Malwarebytes Anti-Malware</a>.</p>
<p>It&#8217;s important that you keep your security programs up to date. I highly recommend downloading the <a title="Web of Trust" href="http://www.mywot.com/" target="_blank">WOT (Web of Trust)</a> add-on for IE and/or Firefox. The WOT add-on warns you about risky sites before you click.</p>
<p>Check out other <a title="Free Security Tools" href="http://www.techjaws.com/15-free-internet-security-utilities-and-programs/">free security utility tools</a>.</p>
<p><strong>Related Articles</strong>:<br />
<a title="How to Remove and Avoid Rogue Applications" href="../how-to-remove-and-avoid-rogue-applications/">How to Remove and Avoid Rogue Applications</a><br />
<a title="Rogue Software Rising at an Alarming Rate" href="../rogue-software-rising-at-an-alarming-rate/">Rogue Software Rising at an Alarming Rate</a><br />
<a title="Beware of Misleading Applications" href="../beware-of-misleading-applications/">Beware of Misleading Applications</a><br />
<a title="How to Remove Security Tool Virus" rel="bookmark" href="../how-to-remove-security-tool-virus/">How to Remove  Security Tool Virus</a></p>
<div style='display:none' id="post-refEl-8071"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/removing-rogue-fake-antivirus/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>How to Remove AntivirusDemoFraud &#8211; Rogue Antivirus</title>
		<link>http://www.techjaws.com/how-to-remove-antivirusdemofraud-rogue-antivirus/</link>
		<comments>http://www.techjaws.com/how-to-remove-antivirusdemofraud-rogue-antivirus/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 17:24:38 +0000</pubDate>
		<dc:creator>Frank Jovine</dc:creator>
				<category><![CDATA[Fake Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AntiVirus Demo Fraud]]></category>
		<category><![CDATA[How to Remove AntivirusDemoFraud]]></category>
		<category><![CDATA[Rogue Antivirus]]></category>
		<category><![CDATA[Scam]]></category>

		<guid isPermaLink="false">http://www.techjaws.com/?p=7724</guid>
		<description><![CDATA[AntivirusDemoFraud is a fake antivirus application. This security risk can be downloaded by other threats on the computer or by clicking on certain Internet advertisements, but it must be manually installed. When a user downloads AntivirusDemoFraud and runs a scan, the program reports false scan alerts. The program than tries to fool the user in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>AntivirusDemoFraud</strong> is a <strong>fake antivirus</strong> application. This security risk can be downloaded by other threats on  the computer or by clicking on certain Internet advertisements, but it  must be manually installed. When a user downloads <strong>AntivirusDemoFraud</strong> and  runs a scan, the program reports false scan alerts. The program than  tries to fool the user in purchasing the full license to remove the  false errors.</p>
<p><strong>Name</strong>: AntivirusDemoFraud<br />
<strong>Risk Impact</strong>: Medium<br />
<strong>Systems Affected</strong>: Windows 98, Windows 95, Windows XP,  Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000<br />
<strong>Behavior</strong>: The program reports false or exaggerated  system security threats on the computer.</p>
<p><a href="http://www.techjaws.com/wp-content/uploads/2010/03/antivirusdemofraud.jpg"><img class="alignnone size-full wp-image-7725" style="border: 0pt none; margin: 0px;" title="antivirusdemofraud" src="http://www.techjaws.com/wp-content/uploads/2010/03/antivirusdemofraud.jpg" alt="How to Remove AntivirusDemoFraud" width="500" height="422" /></a></p>
<p><strong>How to Remove AntivirusDemoFraud</strong><br />
The following instructions pertain to all current and recent Symantec  antivirus products, including the Symantec AntiVirus and Norton  AntiVirus product lines.</p>
<ol>
<li>Disable System Restore (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to the registry.</li>
</ol>
<p>For specific details on each of these steps, read the following <a title="How to Remove AntivirusDemoFraud" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-032913-3556-99&amp;tabid=3" target="_blank">instructions</a>.</p>
<p>If you do not have Norton Antivirus, you can download a free copy of <a title="Malwarebytes - Anti-Malware" href="http://www.malwarebytes.org/mbam.php" target="_blank">Malwarebytes’  Anti-Malware</a> to remove this software.</p>
<p>See more fake antivirus removal instructions <a title="Fake Antivirus  Removal" href="../category/security/misleading-applications-security-2/">here</a>.</p>
<div style='display:none' id="post-refEl-7724"></div>]]></content:encoded>
			<wfw:commentRss>http://www.techjaws.com/how-to-remove-antivirusdemofraud-rogue-antivirus/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
