R3v3rs3e's Blog

Rogue AV: Antivirus Plus

Posted by Steve Espino on July 30, 2009

Here’s another Rogue AV using the same animated system scan on the internet browser as the one in a previous post

aplus_scan

In some instances, Antivirus Plus uses this animated scan instead:

aplus_scan2

It also uses one of those warnings that look oh so genuinely sincere:

aplus_warning

Then of course downloading and installing the rogue app give us the usual scan results:

antivirusplus

Here’s a list of domains currently serving this rogue app:


hxxp://adoimi.cn
hxxp://yourguardpro.cn
hxxp://yourcheckpoisonpro.cn
hxxp://yourfriskviruspro.cn
hxxp://antivirusplus09.com
hxxp://antivirusplus-ok.com
hxxp://addedantiviruspro.com

aplus

Because of the same animated system scan that they use, I reckon System Security and Antivirus Plus are two related rogue apps.

2 Responses to “Rogue AV: Antivirus Plus”

  1. [...] uses the same tactic as seen on earlier posts here and here where the website claims to scan the unsuspecting user’s computer, detects heaps of [...]

  2. [...] has been seen to be using a bogus My Computer online scan similar to ones we’ve seen here, here and [...]

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

 
Follow

Get every new post delivered to your Inbox.