Spyware Confidential

Larry Dignan, Jason Perlow, Tom Steinert-Threlkeld

New rogue anti-spyware and SpySheriff clone

By | March 9, 2006, 9:26pm PST

These rogue anti-spyware programs seem to multiply like rabbits. Just 2 days ago I wrote about Spy-Shield, an anti-spware app that installs adware from BestOffersNetwork Then yesterday SunbeltBLOG featured another new rogue anti-spyware app named BraveSentry. The Sunbelt researchers found a domain running exploits and force installing not just one rogue anti-spyware app but two.  Maybe pushers thought two rogues would be more convincing to frighten the user into buying one of them? The domain running the exploits is a known CoolWebSearch domain, Game4all(dot)biz (link to whois) which is hosted in Russia. SunbeltBlOG has screenshots of the hijacked desktops with BraveSentry and AlfaCleaner. The BraveSentry website is hosted at InterCage, formerly Atrivo, which I blogged about previously, and its neighbor on the same IP (69.50.166.195)  is anosurfer.com, another site for SpySheriff. (Links are to whois info, not to the sites.)

And… speaking of SpySheriff, which got number 2 place on the top 10 rogue anti-spyware of 2005, another SpySheriff clone emerged today - PestWiper, which also "happens" to be hosted at InterCage.

Wouldn’t you know it, there’s already a complaint on an anti-spyware forum about being hijacked by BraveSentry. I wouldn’t be surprised to see similar complaints about PestWiper soon. I believe the Antispyware Conspiracy that Mark Russinovich (of Sony DRM rootkit fame) wrote about here is very real. 

On a side note, I received an email today from a vendor whose anti-spyware program is listed on the Rogue/Suspect Anti-Spyware page. He was, of course, complaining about his product being listed, but one of the statements in is email really got my attention:

In our opinion, the Adware is one of the best ways to advertise antispyware product because users who got Adware would need a way to clean and protect their computers.

If I understand that correctly, he is saying that it’s not only ok, but good, to use adware to advertise antispyware products. Fascinating, isn’t it? And that’s not one of the problems noted with his app, either.  Not  yet, at least…

If anyone lands here from a search engine and has been hijacked by any of the above mentioned rogues, you can get help with removal at one of the anti-spyware sites listed on this page.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Biography

Suzi Turner is webmaster and owner of SpywareWarrior.com, a comprehensive site that includes a spyware help forum, spyware blog and reviews of anti-spyware software by noted spyware expert Eric L. Howes. Suzi became angry about spyware in 2002 after being infected by a drive-by-download of a browser hijacker and unwanted adware/spyware and decided to help others in the same predicament. In April 2005, Microsoft awarded Suzi its MVP (Most Valued Professional) Award in recognition of her work to help internet users protect their privacy by removing and preventing spyware. Suzi is also a nurse for a national disability management company.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
1
Comments

Join the conversation!

0 Votes
+ -
Bravesentry
Basjanssen 13th Mar 2006
My dad's computer is heavily infected with Bravesentry and AlfaCleaner. This malicious adware is taking up all the cpu power (old pc) and mouse power (I keep clicking away messages to buy bravesentry). Please please can someone help me or give me some advice in how to get rid of this adware... I've tried running spyware doctor in WindowsXP Safe Mode, it removed a lot of crap but rebooting in normal mode simply seems to start up all the crap again... What to do what to do?! :S Thanks.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix