Rogue security software is a form of computer malware that deceives or misleads users into paying for the fake or simulated removal of malware. Rogue security software, in recent years, has become a growing and serious security threat in desktop computing.
Propagation
Rogue security software mainly relies on social engineering in order to defeat the security built into modern operating system and browser software and install itself onto victims' computers.
Most have a Trojan horse component, which users are misled into installing. The Trojan may be disguised as:
- A browser plug-in or extension (typically toolbar)
- An image, screensaver or archive file attached to an e-mail message
- Multimedia codec required to play a certain video clip
- Software shared on peer-to-peer networks
- A free online malware scanning service
Some rogue security software, however, propagate onto users computers as drive-by downloads which exploit security vulnerabilities in web browsers or e-mail clients to install themselves without any manual interaction.
Operation
Once installed, the rogue security software may then attempt to entice the user into purchasing a service or additional software by:
- Alerting the user with the fake or simulated detection of malware or pornography.
- Displaying an animation simulating a fake system crash and reboot.
- Selectively disabling parts of the system to prevent the user from uninstalling them. Some may also prevent anti-malware programs from running, disable automatic system software updates and block access to websites of anti-malware vendors.
- Installing actual malware onto the computer, then alerting the user after "detecting" them. This method is less common as the malware is likely to be detected by legitimate anti-malware programs.
Some rogue security software overlaps in function with scareware by also:
- Presenting offers to fix urgent performance problems or perform essential housekeeping on the computer.
- Scaring the user by presenting authentic-looking pop-up warnings and security alerts, which may mimic actual system notices. These are intended to leverage the trust of the user in vendors of legitimate security software.
Sanction by the FTC and the increasing effectiveness of anti-malware tools since 2006 have made it difficult for spyware and adware distribution networks—already complex to begin with—to operate profitably. Malware vendors have turned instead to the simpler, more profitable business model of rogue security software, which is targeted directly at users of desktop computers.
Rogue security software is often distributed through highly-lucrative affiliate networks, in which affiliates supplied with Trojan kits for the software are paid a fee for every successful installation, and a commission from any resulting purchases. The affiliates then become responsible for setting up infection vectors and distribution infrastructure for the software. An investigation by security researchers into the Antivirus XP 2008 rogue security software found just such an affiliate network, in which members were grossing commissions upwards of $USD150,000 from tens of thousands of successful installations per month.
Law enforcement
In December 2006, the Washington Attorney General announced that it had reached settlement in a suit against Secure Computer LLC, the White Plains-based vendor of the Spyware Cleaner rogue security software, under the Computer Spyware Act passed by the Washington State Legislature in 2005. Secure Computer, under consent decree, agreed to pay more than $USD75,000 in restitution to consumers.
In December 2008, the US District Court for Maryland—at the request of the FTC—issued a restraining order against Innovative Marketing Inc, a Kiev-based firm producing and marketing the rogue security software products WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus. The company and its US-based web host, ByteHosting Internet Hosting Services LLC, had their assets frozen, were barred from using domain names associated with those products and any further advertisement or false representation.
Law enforcement has also exerted pressure on banks to shut down merchant gateways involved in processing rogue security software purchases. In some cases, the high volume of credit card chargebacks generated by such purchases has also prompted processors to take action against rogue security software vendors.
Partial list of rogue security software
The following is a partial list of rogue security software, most of which can be grouped into families . These are functionally-identical versions of the same program repackaged as successive new products by the same vendor.
References
- ^ a b c d "Microsoft Security Intelligence Report volume 6 (July - December 2008)". Microsoft. 2009-04-08. pp. 92 . http://www.microsoft.com/downloads/details.aspx?FamilyID=aa6e0660-dc24-4930-affd-e33572ccb91f&displaylang=en . Retrieved 2009-05-02 .
- ^ a b Doshi, Nishant (2009-01-19), Misleading Applications – Show Me The Money! , Symantec , https://forums2.symantec.com/t5/blogs/blogprintpage/blog-id/security_risks/article-id/53 , retrieved 2009-05-02
- ^ Doshi, Nishant (2009-01-21), Misleading Applications – Show Me The Money! (Part 2) , Symantec , https://forums2.symantec.com/t5/blogs/blogprintpage/blog-id/security_risks/article-id/54 , retrieved 2009-05-02
- ^ a b "Free Security Scan" Could Cost Time and Money , Federal Trade Commission, 2008-12-10 , http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt121.shtm , retrieved 2009-05-02
- ^ http://tech.yahoo.com/blog/null/107193
- ^ Testimony of Ari Schwartz on "Spyware" , Senate Committee on Commerce, Science, and Transportation, 2005-05-11 , http://www.cdt.org/testimony/20050511schwartzspyware.pdf
- ^ Leyden, John (2009-04-11). "Zango goes titsup: End of desktop adware market". The Register . http://www.theregister.co.uk/2009/04/21/zango . Retrieved 2009-05-05 .
- ^ Cole, Dave (2006-07-03), Deceptonomics: A Glance at The Misleading Application Business Model , Symantec , https://forums2.symantec.com/t5/blogs/blogprintpage/blog-id/grab_bag/article-id/5 , retrieved 2009-05-02 ...
Free Anti-Spyware software downloads
Download free antispyware software, spyprotect, privacy shield, spyware, malware, adware removal utilities with reviews - Security: Anti-Spyware
AVG Free - Download Free Antivirus and Antispyware for Windows 7 ...
AVG Free provides you with basic antivirus and antispyware protection for Windows and is ... Protection against viruses and spyware (antivirus and antispyware) Fast, effective security ...
Free anti-spyware - 1-2-3 Spyware Free - Protecting from spyware and ...
Free anti-spyware - Free anti-spyware ... Keep your PC protected from Internet threats with a free and easy anti-spyware and antivirus solution.
AVG Free - AVG Anti-Spyware and AVG Anti-Rootkit are no longer ...
Antivirus and internet security protection for home and business. 24/7 support and high-speed automatic updates. Products ranging from maximum protection, to basic antivirus ...
Ad-Aware by Lavasoft - Antivirus software, free spyware removal ...
Providers of the most downloaded anti-virus and free spyware removal software, Ad-Aware. Additional award-winning security products for both home and business include firewall ...
Free Antivirus Tools - Trend Micro USA
Scan for free right now! HouseCall 7 is a major redesign of this highly popular tool. ... Scan your computer to find settings changed by spyware, malware or other unwanted programs.
avast! - Download antivirus software for spyware and virus protection
Download avast! antivirus software a complete virus protection with anti-spyware technology offering full desktop security including a resident shield. It is available as a free ...
Free anti-spyware comparison
Spyware parasites are among the most dangerous and prevalent malicious programs that severely affect our privacy and harm our computers. These threats are like spies that appear in ...
Free spyware removal and spyware protection - Spyware Terminator
Download Spyware Terminator, a free spyware removal and spyware protection program with integrated antivirus. Remove spyware, adware, viruses, trojans, keyloggers, home page ...