Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Click here for the current Blog

September 27, 2010

Is it MS Security Essential or Not?


We’ve just come across another piece of rogueware appearing as the security program, MS Security Essentials.  We have already updated for this threat and posted a description for Win32.Rogue.FakePAV.3 here.  In my professional opinion, I believe we will continue to see an increase in rogueware appearing to be MS Security Essentials, thus blurring the lines between what is real and what is not and confusing the end user even more.  It is a very old trick but one that has unfortunately proven successful. 

Thirtyseven4 Antiivrus Protects Against MS-Security-Essentials

posted Steven Sundermeier

September 22, 2010

Are Malware Authors Suffering from “Writers” Block?


Yesterday we updated for a new piece of Rogueware that has the look and feel of similarly named Fraud Tools such as Digital Protection, Defense Center, Protection Center, Data Protection, etc.  As I have posted numerous times, Thirtyseven4 aggressively seeks out and eliminates such threats daily.  Have you wondered what will happen when these malware authors use up all the possible naming combinations (ie. Security, Data, Defense, Protection, Suite, Tools, etc.)? Well, if this latest Rogueware is an indication I guess they go back to the basics, as the newly updated Rogueware named “Antivirus” shows.  A complete description of “Antivirus”, can be seen here.  A snapshot is shown below:

Thirtyseven4 Antivirus Protects Against Antivirus

posted by Steven Sundermeier

September 16, 2010

Back on the Defensive


Earlier this week we updated for a new variation of Defense Center and incorporated complete removal routines within Thirtyseven4 Antivirus.  It seems like there is a fresh wave of fake security applications making their way online.  Thirtyseven4 customers need not worry about this threat or similar ones.  Our team stands committed in prevention, detection and removal of these forms of malware.  We’re one of only a select few companies that offer full removal routines (including system restoration, registry cleaning, etc) without the need for dedicated security tools or 3rd party applications.

An example of Defense Center is below:

Thirtyseven4 Antivirus Protects Against Defense Center

A complete description of TrojanDownloader.FraudLoad.xe can be seen by clicking here.

posted by Steven Sundermeier

September 10, 2010

Worm.Visal.B Reportedly Infects ABC/Disney, Coca Cola and Others


Yesterday, we became aware (and quickly updated) for a new Internet worm (Worm.Visal.B) that was seen spreading online by extracting the email addresses from an infected users address book. The noted email contains the subject lines “Here you have” or “Just for you” and the body of the message contains a link to a file that misleading appears to be a PDF file. However, the link in the email does not actually point to the promised PDF, but instead redirects to a script that infects the computer with the new worm...that is, if... the user agrees to install the file. Once the worm infects the computer it will propagate itself by sending to all the emails in the address book.

According to the following news story, Worm.Visal.b was successful at infecting a few well known companies including, ABC/Disney, Coca Cola and NASA.  Click here for a link to the story.

Thirtyseven4 customers are fully protected against this threat. A full description can be seen from clicking here.

posted by Steven Sundermeier

September 10, 2010

New Variation of Security Suite Making Its Rounds


I recently came across a new piece of polymorphic rogueware, FakeAV.SecuritySuite the other day and like its earlier forms (ie. Antivirus Soft, Antispyware Soft, Security Tools, etc) when it becomes active in memory the affected machine will no longer be able to execute files with the extension .exe.  Given its polymorphic properties, the name of the dropped file will change with every execution. The file gets executed when the file gets renamed to iexplorer.exe.

Thirtyseven4 customers need not worry as an update has already been posted for this fake security tool.  Any non-thirtyseven4 customer can also remove this infection by dropping a line to service@thirtyseven4.com and requesting a dedicated removal tool.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware  Protects Against Security Suite

posted by Steven Sundermeier

September 3, 2010

Wake-up Call On Your Desktop

Imagine waking up, sitting down at your computer and finding your desktop background has been changed to the following:

Thirtyseven4 Antivirus Protects Against Trojan.Krap

The possibility exists for this to happen if you’ve become infected with Trojan.Krap.an.  Thirtyseven4 customers need not worry as Thirtyseven4 Antivirus has been updated for this trojan.  You can read a complete description of Trojan.Krap.an by clicking here.

posted by Steven Sundermeier

August 30, 2010

Network Access Control (NAC) Scareware


Does all Scareware resemble fake antivirus software?   This was a question I was recently asked.  The simple answer is no.  We have seen, regularly update Thirtyseven4 Antivirus and protect our customers from Scareware that resemble many forms of security software other than just antivirus software.  In fact, we just updated our database for the latest variants of FraudTool.NetCotrol.  This Fraud Tool pretends to be a fake NAC application called “Network Control”.

Here is a screenshot of Network Control:

Thirtyseven4 Protects Against Network Control

A complete description of FraudTool.NetCotrol can be seen by clicking here.

posted by Steven Sundermeier

August 27, 2010

THE DOCTOR IS BACK


In our daily tracking of Rogueware applications, it appears that the fake security software AntiMalware Doctor has resurfaced (Trojan.Oflica.dt).  This variation has been altered just enough to be missed by many antivirus scanners on the market. Thirtyseven4 customers need not worry as we offer full protection against this threat and future threats with our proactive behavioral analysis scanner (built within Thirtyseven4 Antivirus) called DNA Scan.

Even as flu season rapidly approaches, this is one “doctor” you won’t want to see.

Thirtyseven4 Protects Against AntiMalware Doctor

posted by Steven Sundermeier

August 20, 2010

Thirtyseven4 Antivirus Protects Against Wireshark Antivirus


We’ve recently updated and posted a description for a new trojan named Trojan.Wireshark.A.  When this malicious file is ran it will install a piece of Scareware dubbed Wireshark Antivirus.  Wireshark Antivirus was developed to execute automatically on every restart. It will perform a fake scan on the system and falsely states that your machine is infected.  It will also claim that these stated infections will be removed only after you purchase a full version of the software. I’m sure you’ve probably heard that before.  An annoyance of this particular scareware is that Wireshark Antivirus will block nearly all legitimate programs, even applications such as notepad and wordpad.  If a user attempts to open an application it will state that it is infected. It will also display many fake alerts and pop-ups with misleading information.

Thirtyseven4 Antivirus has been updated to detect, prevent and remove Wireshark Antivirus.

Snapshot of Wireshark Antivirus:

Thirtyseven4 Antivirus Protects Against Wireshark Antivirus

posted by Steven Sundermeier

August 16, 2010

OFF THE TOPIC - COCA COLA AND ITS FANTA BRAND


Last week was an extremely busy (and yet very exciting) week for myself and everyone else here at Thirtyseven4. Given this, I know I missed out on a blog or two on a few important security announcements but you can get a brief recap by following the links below:
Microsoft's August Security Bulletin Release and
Apple's emergency security patch for the iPhone, iPad and iPod Touch.

However, to start this week I thought I would blog on something fun, cool and completely off the security topic for a change.  As many of you know, Thirtyseven4 has partnered with a non-profit organization, Remember Nhu.  Remember Nhu is an organization committed to keeping girls from falling prey to the s.e.x trade industry.  One of the young ladies associated with Remember Nhu, who helps raise money by organizing fund raising concerts and performing at them, is named Shuree. Shuree has a professional voice.

Long story short, Shuree has reached the top 10 out of hundreds and hundreds of people nationally for a chance to make TV commercials for Coca Cola on their Fanta brand. Pretty cool stuff.  If you're interested I am posting a link to her video for you to check out (located on the fanta website) and if you desire you can "vote" for her. The top 3 ladies with the most votes advance to the next round.  She would make a wonderful representative.

When you click the link below you will need to click "Log In" and then click "Not Registered."  They will ask for your email and for you to set a password.  Then you are set to vote once per day for Shuree. Of course, only vote if you are comfortable with providing the above information. 

Vote for Shuree

posted by Steven Sundermeier

August 9, 2010

New Wave of Rogueware Exploiting Retail Stores


It appears a recent wave of newly detected Rogueware is once again targeting retail outlets- this time examples include Macy’s and Costco. Users will receive an email in their inbox appearing to be coming from one of these popular store chains.  The email will contain a hyperlink that if clicked on will redirect the user unknowingly to: hxxp://ho[xxxx]ami.cz.cc/scanner5/?afid=24

This link prompts the user to download a file called “antivirus_2.exe”.  If this file gets downloaded and installed the user will inadvertently be installing the Rogueware “Desktop Security 2010”.  I’ve included an example screenshot below:

 Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware  - Protection Against Desktop Security 2010

As always, it is our recommendation here at Thirtyseven4 that you should never blindly click on a link within an unsolicited email.

posted by Steven Sundermeier

August 2, 2010

Scareware Support?


For months I have been blogging on the increasing scareware plague.  Given the situation, we now have a dedicated team sweeping the Internet for such malware helping to keep our Thirtyseven4 users safe and sound.  Some of the more interesting things we’ve noticed is how more and more Scareware creators are incorporating “support” in to their creations.  Yes, support.  I have included a screen shot below of our replication of a piece of Scareware called “Security Master AV” and its included support.  A full description of Security Master AV can be seen at:

http://www.thirtyseven4.com/trojandropper_drooptroop_dur.html or
http://www.thirtyseven4.com/trojan_fakevimes_a.html

Thirtyseven4 Antivirus Protects Against Security Master AV

posted by Steven Sundermeier

Archived Blogs

June 1, 2010 - July 31, 2010
April 1, 2010 - May 31, 2010
January 2010 - March 2010

 

 

Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4