PDA

View Full Version : Watch out for "KVMSecure"


vwestlife
May 21st, 2008, 02:24 PM
One of our computers at work got infected with "KVMSecure". It masquerades as a Microsoft-esque spyware/virus removal utility, using Windows XP colors and fonts and a close imitation of the Windows Defender multicolored shield logo, and then immediately scares the user with fake spyware/virus warnings and offers to run its own "scanning" process, which actually infects your computer with all the nasty stuff it claims to remove. Ultimately the infection was so bad that our IT guys decided to just wipe the hard drive and reinstall Windows. Beware!! :(

http://www.pchubs.com/blogs/wp-content/uploads/2008/05/kvmsecure-site.gif

http://www.pchubs.com/blogs/wp-content/uploads/2008/05/kvmsecure.gif

vwestlife
May 21st, 2008, 03:02 PM
Doing some research on the web, it turns out KvmSecure is a close cousin of so-called "XP Antivirus 2008", among many other fake system cleanup utilities which belong to the "zlob" trojan class. Usually the user is tricked into installed a "video codec" which then installs the trojan and then all hell breaks loose.

As always, tread carefully on the web and make sure your browser is set to block or at least warn you about any unsolicited downloads!

DimensionDude
May 22nd, 2008, 02:23 PM
Hmm...I hadn't heard of this, but I think that the oddly worded phrases and the spelling errors would be a hint that something wasn't quite right.

Kent

vwestlife
May 22nd, 2008, 09:45 PM
Hmm...I hadn't heard of this, but I think that the oddly worded phrases and the spelling errors would be a hint that something wasn't quite right.

Kent
Rogue security software is a huge scam right now: scare people into thinking their computer is infected, and then make them pay to get the "full" version of the software in order to remove the "infection." And the bad ones actually do infect your computer.

Here's a blog which mentions some of the latest ones:

http://www.majauskas.com/

Vlad
May 22nd, 2008, 10:00 PM
Seriously though, "Founded Spyware" Common Sense tells you something is not right when software that markets itself as security software has 2nd grade grammar errors.