Skip to Content

Submit your nominations for the Luxist Awards' Best in Decor
AOL Tech

Filed under: Security, Windows, Troubleshooting, DLS 101

DLS 101 - How to spot a fake Windows antivirus program


One of the most common problems I tackle on Windows computers is the removal of rogue antivirus programs. Just what is a rogue antivirus? It's malware that disguises itself as a legitimate antivirus program.

Unlike Avast, AVG, Kaspersky, Norton, or any of the other real antivirus options out there, a rogue will do nothing to protect you. Rather, it's going to try to deceive you into paying for a full version or removal tool. It may even open a backdoor to your system and start downloading other annoying, nasty programs.

How do these programs get on people's computers in the first place? Usually through deceptive pop-ups on web. Often these "alerts" will try to trick you into thinking:
  • porn and illegal files have been found on your computer
  • a scan has found virus and malware infections on your system
  • your system is totally unprotected
They're all scare tactics designed to get you to clicking something that you really don't want to click. Some go to great lengths to deceive, copying actual Windows screens as closely as possible.
Here are some things to look for:
  • cheesey names - never mind the old adage, with these programs you usually CAN judge the book by its cover. Rogue antivirus programs typically use names like Antivirus 360, WinAntivirus 2009, Spyware Police, SpywareProtect, etc.

    Wikipedia has a huge list of known fake programs. It also helps to get familiar with big-name, legitimate software (like these free antivirus programs for Windows).

    Remind yourself that if you don't recognize the name, don't click.

  • alerts that just don't belong - Windows will tell you if you're not running antivirus software or the definitions are out of date, but it won't tell you that an infection has been found. Windows Defender will pop up alerts, but not Windows itself or the Windows Security Center. Alerts that claim Windows has found infected files are pulling your leg.

  • poor grammar - Windows has its weak points, but real system messages are usually very well written and clear. Alerts from rogue apps don't have the same attention to detail.

  • bogus scanning - lots of these apps pretend to scan your system and find all kinds of infected files. Watch what folders and files are being scanned and see if they match the infected files being found.

    If the scan is going through c:\windows\ and infected items in folders like c:\temp or c:\documents and settings\ are popping up, it's bogus. Real virus scanners will display infected items as soon as they find them in the folder that's currently being scanned - not random stuff from who knows where.
How do you know if you've already been tricked into installing one of these applications?
  • your wallpaper has been changed and the image says something about being infected
  • every time you reboot a scan window pops up
  • whenever the scan completes, you're asked to register or pay in order to remove the infections
If this sounds like your system, take a look at this list of programs which help you clean up your own messes. They just might save you a trip to the repair shop!

Reader Comments (Page 1 of 2)

Featured Time Waster

The World's Hardest Game 2.0 - Time Waster

So, just how good at time waster games are you? Think you've got the stuff? Well, The World's Hardest Game 2.0 doesn't think you do. Yes, amazingly, it's possible to have a sequel to a game called "The World's Hardest Game". It doesn't seem logically possible, since if the first one was actually the world's hardest, how could another one come along and share the moniker? It made me doubt the name in the first place. That is, until I tried the game. The mechanics of the game are very simple. You are a small red square, ...

View more Time Wasters

Featured Galleries

Defective by Design, London: Protest Pictures
Microsoft Security Essentials
Chromium Pre-Alpha on CrunchBang Linux
Safari 4 Beta
10 Firefox themes that don't suck
IE8 RC1
Download Squad at the Crunchies After-Party
Download Squad at the Crunchies
WordPress 2.7
Cooking Mama: Mama Kills Animals
Windows 7 Hands On
Comodo Internet Security
Android First-look: Amazon.com MP3 Store
Android First-look: Twitroid
Google Reader Android
Android Hands-On
Twine 1.0
Photoshop Express Beta
Mozilla Birthday Cake
Palm stuff
Adobe Lightroom 1.1

 


Follow us on Twitter!

Flickr Pool

www.flickr.com

More Tech Coverage

AOL Radio