<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>certifiedbug.com &#187; Scareware Rogues</title>
	<atom:link href="http://certifiedbug.com/blog/category/scareware-rogues/feed/" rel="self" type="application/rss+xml" />
	<link>http://certifiedbug.com/blog</link>
	<description>Consumer Security on the web, information to assist you in practicing safe computing</description>
	<lastBuildDate>Thu, 29 Jul 2010 22:26:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Rogue-Security Essentials 2010</title>
		<link>http://certifiedbug.com/blog/2010/02/25/rogue-security-essentials-2010/</link>
		<comments>http://certifiedbug.com/blog/2010/02/25/rogue-security-essentials-2010/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 21:18:49 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=3395</guid>
		<description><![CDATA[Rogue security products use false advertising, drop malware and often have a similar name or appearance to legitimate security software. Scareware has already mimicked the Windows Security Center. This one mimics Microsoft Security Essentials and calls itself â€œSecurity Essentials 2010â€. Microsoft Malware Protection Center. As we in the MMPC have always been quick to point [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2010/02/25/rogue-security-essentials-2010/">Rogue-Security Essentials 2010</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Rogue security products use false advertising, drop malware and often have a similar name or appearance to legitimate security software.</p>
<p>Scareware has already mimicked the Windows Security Center. This one mimics Microsoft Security Essentials and calls itself â€œ<em>Security Essentials 2010</em>â€.</p>
<p>Microsoft Malware Protection Center.</p>
<blockquote><p>As we in the MMPC have always been quick to point out, Microsoft Security Essentials can be downloaded and used without charge by users running genuine Windows (from here: http://www.microsoft.com/security_essentials/). So anything mimicking Microsoft Security Essentials but asking for any sort of payment is clearly Up To No Good.</p></blockquote>
<p>Screen-shots and <a href="http://blogs.technet.com/mmpc/archive/2010/02/24/if-it-calls-itself-security-essentials-2010-then-it-s-possibly-fake-innit.aspx">more</a> information at the MMPC Threat Research &#038; Response Blog.</p>
<p>Microsoft detects the imposter as Trojan:Win32/Fakeinit. Encyclopedia <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Fakeinit">here</a></p>
<p><a href="http://certifiedbug.com/blog/category/scareware-rogues/">http://certifiedbug.com/blog/category/scareware-rogues/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2010/02/25/rogue-security-essentials-2010/">Rogue-Security Essentials 2010</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2010/02/25/rogue-security-essentials-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Antivirus adds &#8220;Support&#8221;</title>
		<link>http://certifiedbug.com/blog/2010/02/15/fake-antivirus-adds-support/</link>
		<comments>http://certifiedbug.com/blog/2010/02/15/fake-antivirus-adds-support/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 19:37:23 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Social-Engineering]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=3332</guid>
		<description><![CDATA[Rogue security programs usually pop up a screen informing users that their PC is infected with malware. The user, understandably alarmed by the nonstop pop-ups which suddenly appear on their frozen screen, will often click to make a purchase and download the &#8220;fake&#8221; software which claims it will remove the infection. In a nutshell that [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2010/02/15/fake-antivirus-adds-support/">Fake Antivirus adds &#8220;Support&#8221;</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Rogue security programs usually pop up a screen informing users that their PC is infected with malware. The user, understandably alarmed by the nonstop pop-ups which suddenly appear on their frozen screen, will often click to make a purchase and download the &#8220;fake&#8221; software which claims it will remove the infection. In a nutshell that &#8220;is&#8221; the infection and a lucrative business for criminals.  </p>
<p>According to researchers at Symantec the authors of Live PC Care have taken things to the next level. The free trial version of Live PC Care includes a yellow online support button. Clicking on that button connects the potential victim with so-called â€œsupport agentsâ€ who will answer questions about the product via instant message.</p>
<p><a href="http://www.symantec.com/connect/blogs/fake-av-talking-enemy">Fake AV &#038; Talking With The Enemy</a></p>
<p><a href="http://certifiedbug.com/blog/category/scareware-rogues/">http://certifiedbug.com/blog/category/scareware-rogues/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2010/02/15/fake-antivirus-adds-support/">Fake Antivirus adds &#8220;Support&#8221;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2010/02/15/fake-antivirus-adds-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Adware Scanner 2010, rogue with fake credentials</title>
		<link>http://certifiedbug.com/blog/2009/12/16/system-adware-scanner-2010-rogue-with-fake-credentials/</link>
		<comments>http://certifiedbug.com/blog/2009/12/16/system-adware-scanner-2010-rogue-with-fake-credentials/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 17:31:20 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Fake]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=3044</guid>
		<description><![CDATA[Sunbelt Blog: New rogue borrows massively from AV company sites Although the group claims 10 million users world-wide, oddly enough their site was only registered Nov. 25. It seems they also have recruited the entire management team from AVG anti-virus company as well. Right! Article Certifiedbug.com System Adware Scanner 2010, rogue with fake credentials<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/12/16/system-adware-scanner-2010-rogue-with-fake-credentials/">System Adware Scanner 2010, rogue with fake credentials</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Sunbelt Blog: <em>New rogue borrows massively from AV company sites</em></p>
<blockquote><p>Although the group claims 10 million users world-wide, oddly enough their site was only registered Nov. 25.</p>
<p>It seems they also have recruited the entire management team from AVG anti-virus company as well. Right!</p></blockquote>
<p><a href="http://sunbeltblog.blogspot.com/2009/12/10-million-people-will-you-computers_15.html?">Article</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/12/16/system-adware-scanner-2010-rogue-with-fake-credentials/">System Adware Scanner 2010, rogue with fake credentials</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/12/16/system-adware-scanner-2010-rogue-with-fake-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI warns consumers about rogue security programs</title>
		<link>http://certifiedbug.com/blog/2009/12/16/fbi-warns-consumers-about-rogue-security-programs/</link>
		<comments>http://certifiedbug.com/blog/2009/12/16/fbi-warns-consumers-about-rogue-security-programs/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 17:15:34 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=3039</guid>
		<description><![CDATA[Press Release December 11, 2009. The FBI warned consumers today about an ongoing threat involving pop-up security messages that appear while they are on the Internet. The messages may contain a virus that could harm your computer, cause costly repairs or, even worse, lead to identity theft. The messages contain scareware, fake or rogue anti-virus [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/12/16/fbi-warns-consumers-about-rogue-security-programs/">FBI warns consumers about rogue security programs</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Press Release December 11, 2009.</p>
<blockquote><p>The FBI warned consumers today about an ongoing threat involving pop-up security messages that appear while they are on the Internet. The messages may contain a virus that could harm your computer, cause costly repairs or, even worse, lead to identity theft. The messages contain scareware, fake or rogue anti-virus software that looks authentic.</p>
<p>The message may display what appears to be a real-time, anti-virus scan of your hard drive. The scareware will show a list of reputable software icons; however, you canâ€™t click a link to go to the real site to review or see recommendations. Cyber criminals use botnetsâ€”collections of compromised computersâ€”to push the software, and advertisements on websites deliver it. This is known as malicious advertising or â€œmalvertising.â€</p>
<p>Once the pop-up warning appears, it canâ€™t be easily closed by clicking the â€œcloseâ€ or â€œXâ€ buttons. If you click the pop-up to purchase the software, a form to collect payment information for the bogus product launches. In some instances, the scareware can install malicious code onto your computer, whether you click the warning or not. This is more likely to happen if your computer has an account that has rights to install software.</p>
<p>Downloading the software could result in viruses, malicious software called Trojans, and/or keyloggersâ€”hardware that records passwords and sensitive dataâ€”being installed on your computer. Malicious software can cause costly damages for individual users and financial institutions. The FBI estimates scareware has cost victims more than $150 million. </p>
<p>Cyber criminals use easy-to-remember names and associate them with known applications. Beware of pop-up warnings that are a variation of recognized security software. You should research the exact name of the software being offered. Take precautions to ensure operating systems are updated and security software is current. If you receive these anti-virus pop-ups, close the browser or shut down your computer system. You should run a full anti-virus scan whenever the computer is turned back on.</p>
<p>If you have experienced the anti-virus pop-ups or a similar scam, notify the Internet Crime Complaint Center (IC3) by filing a complaint at www.ic3.gov. </p></blockquote>
<p><a href="http://www.fbi.gov/pressrel/pressrel09/popup121109.htm">Pop-Up Security Warnings Pose Threats</a></p>
<p><a href="http://certifiedbug.com/blog/category/scareware-rogues/">http://certifiedbug.com/blog/category/scareware-rogues/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/12/16/fbi-warns-consumers-about-rogue-security-programs/">FBI warns consumers about rogue security programs</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/12/16/fbi-warns-consumers-about-rogue-security-programs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cleaner affiliates gotcha</title>
		<link>http://certifiedbug.com/blog/2009/10/18/cleaner-affiliates-gotcha/</link>
		<comments>http://certifiedbug.com/blog/2009/10/18/cleaner-affiliates-gotcha/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 16:40:35 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Busted]]></category>
		<category><![CDATA[Internet Security]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=2807</guid>
		<description><![CDATA[S!ri, a well known and respected malware fighter in the security community, wrote that some webmasters (cleaner affiliates) regularly use the screenshots that he made after analyzing a rogue, in their own blog posts. The cleaner affiliates write about the dangerousness of the rogue and link to a &#8220;Free&#8221; Scan or &#8220;Free&#8221; Removal tool which [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/10/18/cleaner-affiliates-gotcha/">Cleaner affiliates gotcha</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>S!ri, a well known and respected malware fighter in the security community, wrote that some webmasters (cleaner affiliates) regularly use the screenshots that he made after analyzing a rogue, in their own blog posts.</p>
<p>The cleaner affiliates write about the  dangerousness of the rogue and link to a &#8220;Free&#8221; Scan or &#8220;Free&#8221; Removal tool which may not be free at all. <img src='http://certifiedbug.com/blog/wp-includes/images/smilies/icon_mad.gif' alt=':-x' class='wp-smiley' />  </p>
<blockquote><p>
So I decided to MAKE a picture of a new rogue that does NOT exist: Secure Shield. I post the picture and wait for the &#8220;serious&#8221; guys.</p></blockquote>
<blockquote><p>Those guys are inventing files, folders and keys name.</p></blockquote>
<p><a href="http://siri-urz.blogspot.com/2009/10/secure-shield-fake-rogue.html">Secure Shield fake rogue</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/10/18/cleaner-affiliates-gotcha/">Cleaner affiliates gotcha</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/10/18/cleaner-affiliates-gotcha/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogue-Personal Antivirus</title>
		<link>http://certifiedbug.com/blog/2009/04/17/rogue-personal-antivirus/</link>
		<comments>http://certifiedbug.com/blog/2009/04/17/rogue-personal-antivirus/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 07:18:55 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=2240</guid>
		<description><![CDATA[While performing a search I saw the red warning circle given by Web Of Trust (WOT) to sites they have rated dangerous. Normally one should stop there people but I was digging. In a clean, uninfected virtual machine I opened the url which took awhile to load its nasty stuff and then the popups began. [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/04/17/rogue-personal-antivirus/">Rogue-Personal Antivirus</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>While performing a search I saw the red warning circle given by <a href="www.mywot.com/">Web Of Trust </a> (WOT) to sites they have rated dangerous.</p>
<p>Normally one should stop there people but I was digging. In a clean, uninfected virtual machine I opened the url which took awhile to load its nasty stuff and then the popups began.</p>
<p><img src="http://certifiedbug.com/blog/wp-content/uploads/2009/04/personalantivirus2.png" alt="" title="personalantivirus2" width="431" height="328" class="alignnone size-full wp-image-2243" /></p>
<p><img src="http://certifiedbug.com/blog/wp-content/uploads/2009/04/personalantivirus3.png" alt="" title="personalantivirus3" width="429" height="217" class="alignnone size-full wp-image-2242" /></p>
<p> &#8220;Don&#8217;t close this window if your want you PC to be clean&#8221;   <img src='http://certifiedbug.com/blog/wp-includes/images/smilies/icon_rolleyes.gif' alt=':roll:' class='wp-smiley' />  </p>
<p>Certifiedbug. September 6, 2008.<br />
 <a href="http://certifiedbug.com/blog/2008/09/06/smartantivirus2009-rogue-security-program/">http://certifiedbug.com/blog/2008/09/06/smartantivirus2009-rogue-security-program/</a></p>
<blockquote><p>Harry Waldon has a nice article <a href="http://msmvps.com/blogs/harrywaldron/archive/2008/08/22/malware-close-encounters-close-pop-ups-using-task-manager-to-safely-exit.aspx">Malware Close Encounters &#8211; Close Pop-ups using Task Manager to safely exit</a> which could help users to exit a pop-up install before too much damage is inflicted.</p></blockquote>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/04/17/rogue-personal-antivirus/">Rogue-Personal Antivirus</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/04/17/rogue-personal-antivirus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>advancedprotectionscanner.com et al-rogues deployed</title>
		<link>http://certifiedbug.com/blog/2009/03/22/advancedprotectionscannercom-et-al-deployed/</link>
		<comments>http://certifiedbug.com/blog/2009/03/22/advancedprotectionscannercom-et-al-deployed/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 19:36:19 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=2142</guid>
		<description><![CDATA[The Russian Business Network affiliate involved has established a front company, autonomous system AS48669 NTCOLO-AS NTCOLO, and has been allocated 510 unique IP addresses. AS48669 consists of 105 malware domains, 19 domain name servers, 8 mail servers and 3 fraudulent payment processors. List of current IPs Secure Home Networks Certifiedbug.com advancedprotectionscanner.com et al-rogues deployed<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/03/22/advancedprotectionscannercom-et-al-deployed/">advancedprotectionscanner.com et al-rogues deployed</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><blockquote><p>The Russian Business Network affiliate involved has established a front company, autonomous system AS48669 NTCOLO-AS NTCOLO, and has been allocated 510 unique IP addresses. AS48669 consists of 105 malware domains, 19 domain name servers, 8 mail servers and 3 fraudulent payment processors.</p></blockquote>
<p>List of current IPs <a href="http://securehomenetwork.blogspot.com/">Secure Home Networks</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/03/22/advancedprotectionscannercom-et-al-deployed/">advancedprotectionscanner.com et al-rogues deployed</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/03/22/advancedprotectionscannercom-et-al-deployed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Drop for Rogue &#8216;Internet Antivirus Pro&#8217; Gotscan, user4scan</title>
		<link>http://certifiedbug.com/blog/2009/03/16/drop-for-rogue-internet-antivirus-pro-gotscan-user4scan/</link>
		<comments>http://certifiedbug.com/blog/2009/03/16/drop-for-rogue-internet-antivirus-pro-gotscan-user4scan/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 21:14:08 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Directi]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=2062</guid>
		<description><![CDATA[Redirect from gotscan.com to user4scan.com. &#60;&#8211; Do not go to either. Received typical scareware warnings, rogue was not detected by my anti virus program. The installer repeatably failed, popping up the same windows and freezing the browser. Domain Name: USER4SCAN.COM IP Location: Germany &#8211; Berlin &#8211; Berlin &#8211; Netdirekt E.k Registration Service Provided By: SELLOUT.NAME [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/03/16/drop-for-rogue-internet-antivirus-pro-gotscan-user4scan/">Drop for Rogue &#8216;Internet Antivirus Pro&#8217; Gotscan, user4scan</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Redirect from gotscan.com to user4scan.com. &lt;&#8211; <strong>Do not go to either</strong>.</p>
<p><img src="http://certifiedbug.com/blog/wp-content/uploads/2009/03/user4scan5.png" alt="" title="user4scan5" width="459" height="218" class="alignnone size-full wp-image-2068" /></p>
<p>Received typical scareware warnings, rogue was not detected by my anti virus program. The installer repeatably failed, popping up the same windows and freezing the browser. </p>
<p>Domain Name: USER4SCAN.COM<br />
IP Location: Germany  &#8211; Berlin &#8211; Berlin &#8211; Netdirekt E.k<br />
Registration Service Provided By: SELLOUT.NAME<br />
Creation Date: 12-Mar-2009<br />
Expiration Date: 12-Mar-2010<br />
Domain servers in listed order:<br />
ns2.dnsexit.com<br />
ns1.dnsexit.com</p>
<p>Domain name: gotscan.com<br />
IP Location: Germany &#8211; Berlin &#8211; Berlin &#8211; Netdirekt E.k<br />
ICANN Registrar: 	BIZCN.COM, INC.</p>
<p><em>Edit to add:</em><br />
SELLOUT.NAME<br />
ICANN Registrar: 	Directi Internet Solutions Pvt. Ltd. d/b/a PublicDomainRegistry.com<br />
Created: 	2006-11-08<br />
Expires: 	2009-11-08<br />
Updated: 	2009-02-03</p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/03/16/drop-for-rogue-internet-antivirus-pro-gotscan-user4scan/">Drop for Rogue &#8216;Internet Antivirus Pro&#8217; Gotscan, user4scan</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/03/16/drop-for-rogue-internet-antivirus-pro-gotscan-user4scan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Rogue XpyBurner</title>
		<link>http://certifiedbug.com/blog/2009/02/09/new-rogue-xpyburner/</link>
		<comments>http://certifiedbug.com/blog/2009/02/09/new-rogue-xpyburner/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 08:19:24 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Directi]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1979</guid>
		<description><![CDATA[Scareware Spyburner becomes XpyBurner. From EULA. C. Some of our products may be unsuited to run with other software. We have the right to uninstall incompatible products. We will notify our customers before uninstalling such products. A customer cannot claim a refund if the reason is a requisition or removal of conflicting software. Coexistence of [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/02/09/new-rogue-xpyburner/">New Rogue XpyBurner</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Scareware Spyburner becomes XpyBurner.</p>
<p style="text-align: center;"><img class="size-medium wp-image-1980 aligncenter" title="xpyburner2" src="http://certifiedbug.com/blog/wp-content/uploads/2009/02/xpyburner2-300x86.png" alt="" width="300" height="86" /></p>
<p style="text-align: center;"><img class="size-full wp-image-1981 aligncenter" title="xpyburner1" src="http://certifiedbug.com/blog/wp-content/uploads/2009/02/xpyburner1.png" alt="" width="400" height="174" /></p>
<p style="text-align: center;"><img class="size-full wp-image-1982 aligncenter" title="xpyburner" src="http://certifiedbug.com/blog/wp-content/uploads/2009/02/xpyburner.png" alt="" width="354" height="201" /></p>
<p>From EULA.</p>
<blockquote><p>C. Some of our products may be unsuited to run with other software. We have the right to uninstall incompatible products. We will notify our customers before uninstalling such products. A customer cannot claim a refund if the reason is a requisition or removal of conflicting software.<br />
Coexistence of some products may lead to many unsatisfactory effects as well as to slow the customer&#8217;s system. That is why the usage of XpyBurner requires the uninstallation of products which represent a risk to the system.</p></blockquote>
<p>Uh huh&#8230;</p>
<p>ICANN Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM<br />
Registration Service Provided By: ERDOMAIN.COM<br />
Registrant: PrivacyProtect.org</p>
<p><a href="http://certifiedbug.com/blog/tag/directi/">DIRECTI</a> doesn&#8217;t appear to be cleaning up its act.<br />
Spyware Sucks: <a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668084.aspx">I just knew I&#8217;d find DIRECTI in there somewhere&#8230; </a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/02/09/new-rogue-xpyburner/">New Rogue XpyBurner</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/02/09/new-rogue-xpyburner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Rogue-Total Defender</title>
		<link>http://certifiedbug.com/blog/2009/01/26/new-rogue-total-defender/</link>
		<comments>http://certifiedbug.com/blog/2009/01/26/new-rogue-total-defender/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 17:08:54 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Scareware Rogues]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1933</guid>
		<description><![CDATA[An interesting thing we noticed is that the Rogue did not attempt to scare us into purchasing it, rather telling us that the computer was secure after the scan. The Rogue authors are probably doing this to keep a high amount of Rogue installations active for the purposes of data theft or for hire services. [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/01/26/new-rogue-total-defender/">New Rogue-Total Defender</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><blockquote><p>An interesting thing we noticed is that the Rogue did not attempt to scare us into purchasing it, rather telling us that the computer was secure after the scan.  The Rogue authors are probably doing this to keep a high amount of Rogue installations active for the purposes of data theft or for hire services.</p></blockquote>
<p>PandaLabs Blog: </p>
<p>http://pandalabs.pandasecurity.com/archive/New-Rogue_3A00_-Total-Defender.aspx</p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2009/01/26/new-rogue-total-defender/">New Rogue-Total Defender</a></p>
]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2009/01/26/new-rogue-total-defender/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
