New rogue antivirus app has a hate-on for Malwarebytes

How do you know when your crapware-fighting application has really made it big? When it starts being targeted by rogue antivirus software, of course.
Protection System -- which sounds about as real as The Christopher Guest School for Mixed Martial Arts -- detects MBAM during its bogus scan procedure and declares it malicious. It then offers to remove the threat for the poor sap who doesn't realize what's happening. After clicking ok, the uninstall routine is run and the user is left without what is likely the best tool for removing this pest.
This isn't a new tactic by any means. It's pretty common for engineered nasties to disable and damage antivirus and antimalware programs and mess with your hosts file so you can't update definitions or re-download.
Keep your filthy paws off MBAM, you damn, dirty rogue.
[via Sunbelt Blog]
Get a WordPress.com Blog
So, just how good at time waster games are you? Think you've got the stuff? Well, The World's Hardest Game 2.0 doesn't think you do.
Yes, amazingly, it's possible to have a sequel to a game called "The World's Hardest Game". It doesn't seem logically possible, since if the first one was actually the world's hardest, how could another one come along and share the moniker? It made me doubt the name in the first place. That is, until I tried the game.
The mechanics of the game are very simple. You are a small red square, ...

Reader Comments (Page 1 of 1)
Spedione said 8:21PM on 9-02-2009
How dare they take aim at Malwarebytes!!!!
Reply
jay4 said 9:46PM on 9-02-2009
The screenshot looks exactly like 2 malware infections I took care of last month. "PC AntiSpyware 2010" & "Green AV 2009". Malwarebytes was the only s/w that was able to remove it. Looks like I'll have to keep a copy handy on a flash drive.
Reply
nitrous9200 said 9:59PM on 9-02-2009
I just dealt with this today; it also installs a rootkit which can be easily removed with Gmer. Then you can run ComboFix, SuperAntiSpyware, Malwarebytes et al to remove the rest.
Reply
TurboFool said 1:08AM on 9-03-2009
To be fair, MBAM usually can't remove these infections alone, because they already block it from running. MBAM, Spybot, etc. all get blocked from running by the newest fake AV apps. Really, the only surefire bet for most is to boot into safe mode, run ComboFix first (usually renaming it to something like spaghetti.exe), let it do its thing, and then run MBAM to clean up the rest.
Reply
Nightstar said 2:07AM on 9-03-2009
I fought one like this two week ago for a client. Mallwarebytes could NOT clean it off! Had to backup nuke and rebuild!
Reply
Thunderbuck said 3:32AM on 9-03-2009
I definitely need to find a life when any headline that contains the word "rogue" instantly makes me think it's about WoW...
Reply