Watch out for XPantivirus
One of our earlier blog posts had Roger Thompson of AVG’s Exploit Preventions Labs running through MalwareAlarm in a well produced video. Well, XPantivirus is a new in the wild rogue security program, which comes from the same family of malware,
It uses some clever Javascript coding, just like MalwareAlarm, to force you down the road of running a fake security scan. In record breaking time, it comes back to announce the computer has some very scary looking malware installed, but their product can easily remove them for a nominal license fee. These results are completely bogus and have been faked by design to scare you into handing over your cash – a nice social engineering scam! No legitimate application would make it so hard to cancel out of installing it!
This one is so new that only 5 out of 32 security products used by VirusTotal can detect it. That means a significant proportion of people are currently running a system that cannot detect this nasty.
Don’t go near the website. Don’t install XPantivirus. Don’t give them payment details. Basically, don’t get caught out folks!
We’ll be keeping an eye on how the relevant security vendors respond to this one and will let you know in a follow-up post and vblog entry about security company response times.
Take care folks.
Technorati Tags: downloader, malware, MalwareAlarm, social engineering, Trojan, Virus Total, XP Antivirus, XPAntivirus



March 11th, 2008 at 3:30 pm
I had this parasite. I honestly thought it was a good program until I read this post and a couple more. I used a manual method for removing xpantivirus. Reboot in safe mode then run smitfraudfix. It cleans up all types of Trojans from your computer.
I used a combination of guides for removal:
http://www.spyware-techie.com/xpantivirus-removal-guide/
http://www.bleepingcomputer.com/forums/topic111715.html
these show you step by step for booting in safe mode and using smitfraudfix.
Another manual removal process – http://www.2-viruses.com/remove-xpantivirus
March 11th, 2008 at 4:28 pm
The people who push this scamware should be hung from their personal parts for a very, very, very long time. Scumbags, one and all.
Glad you caught onto it being a bad thing and have managed to get rid of it.
May 27th, 2008 at 3:15 pm
Learn how to code a website dumbasses.