Nov 24

Malware Analysis:

System Fix is pretty good at pretending to be the program you need right now. This illusion is created by means of different techniques that are very similar with those that are usually characteristic of real OS optimization tools. This external trustworthiness is definitely misleading. Once you learn the truth about System Fix application, it will all become obvious. So, here is what you need to know. Although this solution runs PC scanners to see if your system is working at the top of its performance capability, this process does not involve actual monitoring of hardware and software issues. Consequently, whatever System Fix reports after the scan is a lie, including hard drive rotational speed problems, drive C initializing errors, unreadable disks, damaged system files etc. Also, this malware may state another malfunction, displaying a message that reads: “Failed to write all the components for the file \System32\0000[random digits and letters]” (e.g. 0000390c, 00003d6c, 00003a9e etc.). This alert is one of the most frequently noticed signs of this particular infection on a PC.

Oct 04

Malware Analysis:

For your awareness, let us list some messages provided in false popup warnings by Data Restore scareware utility. So here we go: “Hard Drive Failure – The system has detected a problem with one or more installed IDE / SATA hard disks”, “System Error – An error occurred while reading system files”, “Critical Error – Hard drive clusters are partly damaged”. Once again, these are only several of the ads that get constantly generated by Data Restore tricky software when it’s running on your workstation. These ones look and sound pretty scary, don’t they? At least, that’s the idea the creators of this malware had on their minds when making their product what it is. The fake optimization tool under analysis is a part of the huge FakeHDD family, following some very similar-looking and same-acting mendacious apps such as Data Recovery and System Recovery which are just the most recent representatives of this syndicate. When you get one of these, you get pounded by lots of positives informing you of some serious system malfunctions. Data Restore also runs scanners to appear more persuasive. But what’s the point of such behavior of this software, you may wonder?

Sep 14

Malware Analysis:

Data Recovery is one of those applications that make one’s faith in safe computing disappear. The hordes of rogue anti-spyware and optimization software have been a top security issue of the web for years. We can’t help admitting the intensity of their distribution has considerably decreased since June this year, and yet some of those do succeed in breaking through and driving PC users crazy. Data Recovery is a close relative of System Recovery badware. Note even the similarity of their names. On the whole, the new one is just a copy of the latter, having the same interface and acting similarly. However, the arsenal of fake positives involved in this rogue’s campaign is somewhat different as it has expanded to misinform the victims further. For instance, there are now new ads as compared to the predecessors reading “HDD clusters are partly damaged. Segment load failure”, “Failed to save all the components for the file \System32\0000390c” and also this one: “A potential disk failure may cause loss of files, applications and documents stored on the hard disk”.

Sep 04

Malware Analysis:

This post is not about the ‘System Recovery’ some Windows option. It’s about a program posing as a PC performance optimization tool but acting counter to this. As we believe you figured, the name of this software is System Recovery. It has the looks of a legitimate tool for sure but the appeal and glitter may well be misleading, and this is the case. You don’t run into this malicious program until someday you accidentally click some ad on the Internet, being unaware that it is loaded with a heavily dangerous trojan. Although really small, this trojan horse acts as a sort of an installer for its affiliated badware. This is basically how System Recovery gets in. No authorization means you don’t ‘hear’ it knocking on your computer’s door. In other words, the procedure goes past your attention. Then, the scareware begins harming your system to an extent, creating new files and adding Registry keys of its own. From that point on, you will keep seeing more and more false positives imitating attempt to give you assistance in improving the work of your machine.

Aug 27

Malware Analysis:

PC Repair is unauthentic system diagnostics software that looks like an optimizer but acts definitely like a virus. Getting on your nerves and pounding you with the utmost misinformation are this malware’s favorite activities. PC Repair never displays a pre-installation screen, unlike legitimate applications. One of its main weapons is unexpectedness so it uses it to the fullest. Instead of the regular install routine, this program chooses a distorted procedure of stealthily attacking your computer using such auxiliaries as trojans as a springboard for that. So it’s clear you won’t know this pest is inside until it has performed a sufficient bulk of changes for you to actually see their sad consequences. PC Repair triggers startup scanners and random positives that literally yell out loud about your computer’s being at risk. System errors and other various problems, including HDD work issues, will be detected by this utility. Now, what you should not do under any circumstances is believing those ads.

Aug 16

Malware Analysis:

Cyber security analysts are recording an upswing in distribution of the Windows Startup Repair fake system optimization client. We are therefore using the opportunity to caution you and provide some tips to help users avoid this malware and subsequent consequences of its misbehavior. Windows Startup Repair is basically a phony PC diagnostics tool that scans your system for possible malfunctions such as registry errors, file problems and malware issues. You will get to see this counterfeit scan as soon as the virus gets in, which means you can easily track this malady down shortly after its intrusion. It goes without saying the results produced by this kind of scan are untrustworthy. Windows Startup Repair lists the problems it invented on its own – to be specific, it’s the creators of this dangerous and annoying program to blame for this. All they are doing is misleading you into believing some incredible things so that you take bait and pay for the supposed commercial copy of the application.

Jul 13

Malware Analysis:

The only thing System Repair program can do to your computer is damaging it so you will then have to repair it the real way. We have absolutely all judicious grounds to say so because this application is in fact a fake used by criminals to earn heaps of money. System Repair can be classified as a counterfeit optimization utility and has every feature one can come across when dealing with this sort of malign software. It states that you have errors and hardware functioning malfunctions whereas those are just a fiction. Having entered your computer and run a scan, this app returns the results testifying to a really poor performance level. It says your HDD is not responding to system commands; that there has occurred an error reading your Operating System files and similar silly stuff. We want you to know from the start that System Repair reports the issues that you don’t actually have. This done, the badware tells you to perform the errors correction which presupposes passing through a registration procedure first.

Jul 11

Malware Analysis:

Ironically enough, the name of Windows Armour Master implies none of the characteristic features this program actually has. Yet worse, it is a complete contrast to what this abominable application is. This issue is pretty complex and requires a profound insight, which we are going to provide in this article. The problem with any average rogue security product begins with its onset on one’s computer. This intrusion is typically a very intricate procedure and, if successful, brings the virus half-way to its goal. One way or the other, you are not likely to notice the mutations in your system associated with Windows Armour Master’s infiltration. It does change your registry and creates new files but this happens ‘in the heart of your system’s hearts’, so the only symptoms will be those you get to see afterwards. Now, let us have a quick look at the outcomes. Windows Armour Master will start showing deceptive positives with a considerable degree of aggression. It displays scanners producing reports that list many problems ranging from viruses to purely system-related issues.

Jul 09

Malware Analysis:

This post is dedicated to the analysis of Windows Accurate Protector fraudulent application and the potential consequences of its stay on your computer. In case you got this bug on your PC by now, it might be still a secret how and when the badware entered it. We are going to tell you the basics about this virus sample as well as show you how it can be exterminated from your machine. So let’s start with the intrusion (we can hardly pick a different word for this process). Windows Accurate Protector mainly infects computers whose users are actively surfing the Internet. This fact can be explained by the undoubted knowledge that the trojan horses involved in rotating this malware are often latently integrated into the scripts on websites getting a fair number of hits. So if you spend much time online, you are in the risk group. Windows Accurate Protector shows the standard traits as for this kind of malware when operating on your machine. Its ‘weapon’ includes fabricated scanners, false positives and occasional or constant interference with the processes you run or launch.

Jul 08

Malware Analysis:

The capability of modern scareware tools to determine the type of the Operating System injected, as well as to further exploit this information is a trick known for a little more than a year as of now. An example of one such application being in active rotation since yesterdays is Windows Vista Fix. It is a bogus optimizer marketed as a helpful kit for maintaining appropriate condition of one’s computer system. According to the declared data, this program can find potential weaknesses of your OS and repair them using an advanced technology. Have you read the above sentence? If so, forget about it and be advised Windows Vista Fix will not in a million years do any of the things it claims to. It’s enough to know how this utility gets into your workstation to work out the approach to it and the strategy of further ‘collaboration’. Like an average-scale badware of this kind, Windows Vista Fix spreads in the way minimizing the interception prospects. It means, expecting this program to request your authorization for installing itself is vain.