On April 2009 a new rogue appeared which many infected where calling the rogues shown as different names and which Micorosft began naming as FakeRean.
The rogue unlike others in 2009 was different in that the downloader contained a list of rogue names and which then included the OS (Operating System) in the title of the GUI (Graphical User Interface) of the rogue when opened to start its fake scans and scareware tactics of fake alert pop-ups.
On March 2010, the rogue was updated where it then included the year 2010 in the titles. On January 2011, the rogue again was updated and chenged to using 2011 in the titles and then on June of 2011, they replaced the 2011 with 2012.
This rogue is difficult to remove manually as it adds malicous registry entries which hijacks the EXE file associations and rogues file is removed, the infected user can no longer run any EXE applications.
One of the major distributions of this rogue has been by a group who have added their malicious content in sites that offer comments and postings by users, one which was sourceforge GFI SunbeltBlog who had removed the content and Flikr.com which as of 12 August 2011 has yet to remove the malicious content.
Windows XP | Windows 7 | WIndows Vista |
AntiSpyware XP | Antispyware Win 7 | Antivirus Vista |
Antivirus XP 2010 | Antivirus Win 7 | Vista Anti-Spyware |
Total XP Security | Antivirus Win 7 2010 | Vista Anti-Spyware 2011 |
Vista Antivirus XP Antivirus | Total Win 7 Security | Vista Anti-Virus 2011 |
XP Anti Spyware 2010 | Win 7 Anti-Spyware | Vista AntiMalware 2010 |
XP Anti-Spyware | Win 7 Anti-Spyware 2011 | Vista Antispyware 2010 |
XP Anti-Spyware 2011 | Win 7 Anti-Virus 2011 | Vista Antispyware 2011 |
XP Anti-Virus | Win 7 AntiMalware | Vista Antivirus |
XP Anti-Virus 2011 | Win 7 AntiMalware 2010 | Vista Antivirus 2010 |
XP AntiMalware 2010 | Win 7 Antispyware 2010 | Vista Antivirus 2011 |
XP Antispyware 2010 | Win 7 Antispyware 2012 | Vista Antivirus Pro |
XP Antispyware 2012 | Win 7 Antivirus | Vista Antivirus Pro 2010 |
XP Antivirus 2012 | Win 7 Antivirus 2010 | Vista Defender |
XP Antivirus Pro | Win 7 Antivirus 2012 | Vista Defender 2010 |
XP Antivirus Pro | Win 7 Antivirus Pro | Vista Defender Pro |
XP Antivirus Pro 2010 | Win 7 Antivirus Pro 2010 | Vista Guardian |
XP AntivirusPro 2010 | Win 7 Defender | Vista Guardian 2010 |
XP Defender | Win 7 Defender 2010 | Vista Home Security 2011 |
XP Defender 2010 | Win 7 Defender Pro | Vista Internet Security |
XP Defender Pro | Win 7 Guardian | Vista Internet Security 2010 |
XP Guardian | Win 7 Guardian 2010 | Vista Security |
XP Guardian | Win 7 Home Security | Vista Security 2011 |
XP Guardian 2010 | Win 7 Home Security 2011 | Vista Security Tool |
XP Guardian 2010 | Win 7 Home Security 2012 | Vista Security Tool 2010 |
XP Home Security | Win 7 Internet Security | Vista Smart Security |
XP Home Security 2011 | Win 7 Internet Security 2010 | Vista Smart Security 2010 |
XP Home Security 2012 | Win 7 Internet Security 2011 | Vista Total Security 2011 |
XP Internet Security | Win 7 Internet Security 2012 | |
XP Internet Security | Win 7 Security | |
XP Internet Security 2010 | Win 7 Security 2011 | |
XP Internet Security 2010 | Win 7 Security 2012 | |
XP Internet Security 2011 | Win 7 Security Center | |
XP Internet Security 2012 | Win 7 Security Tool | |
XP Security | Win 7 Security Tool 2010 | |
XP Security 2011 | Win 7 Smart Security | |
XP Security 2012 | Win 7 Smart Security 2010 | |
XP Security Tool | Win 7 Total Security | |
XP Smart Security 2010 | Win 7 Total Security 2011 | |
XP Total Security | ||
XP Total Security 2011 |
You can download a free trial of VIPRE Antivirus to remove the FakeRan rogues infections from your PC for no cost by clicking on the link below:
http://www.vipreantivirus.com/Antivirus-Trial/VIPRE-Antivirus/
If you are unable to download and install our malware removal tool because this has infected your computer and is not allowing you to install the program, you can use our VIPRE Rescue Disc here:
http://live.sunbeltsoftware.com
Additional reading:
Sites of the FakeRean