Infesting you with Virus News
 

News

Contributed by: Daniel Stoyanov
Date: March 17, 2010
Daniel Stoyanov
1
Vote
0

A Final Look At MycomGuard Rogue

 

As you already know, MycomGuard is a fake anti-spyware program that pretends to be a real security tool. It is made with the only purpose to scare and confuse the oversuspicious users that their computer is full of viruses and trojans. In this way they are made to buy this non-working piece of software.

Is this threat already known to most antivirus vendors? With the help of VirusTotal (virustotal.com), an online service providing free malware scanning for individual files, we will find out how many antvirus programs detect this program as a rogue.

MycomGuard is installed through MycomGuardSetup.exe file which is 847637 bytes of size and goes with the MD5 signature 40be36343dc0a99757f050e61026f6a5. According to VirusTotal, the installation file MyComGuardSetup.exe is recognized as infection and threat by 14 antivirus vendors out of 40.

Alias Name
Antivirus Vendor
Adware.Win32.MyComGuard!A2 a-squared
FraudTool/Win32.PcCleaner.gen Antiy-AVL
Win32.TRDldr.FraudLo eSafe
Misc/PcCleaner Fortinet
not-a-virus:FraudTool.Win32.PcCleaner Ikarus
not-a-virus:FraudTool.Win32.PcCleaner.q Kaspersky
potentially unwanted program Generic PUP McAfee
potentially unwanted program Generic PUP McAfee+Artemis
probably a variant of Win32/Adware.FakeBye NOD32
W32/FakeAV.LLQ Norman
Trj/CI.A Panda
FraudTool.Win32.PcCleaner.q Sunbelt
Suspicious.Insight Symantec
Adware.PcCleaner.R.847637 ViRobot

Table 1. Aliases of MycomGuard

Let`s take a look at the origin of this fake anti-spyware program. The scam site of the rogue is M y c o m g u a r d . c o m. As you can see from Figure 1 and Figure 2, the website is written in the Korean language. If you don't speak this language, it will be impossible for you to understand what it is advertising and, therefore, quite impossible to download the MycomGuard fake tool.

mcg_homepage.jpg mcg_downloadpage.jpg

 Figure 1. Home Page of MycomGuard                      Figure 2. Download Page of MyComGuard

The domain is registered in the Republic of Korea under the name of STL, a company located in the city of Seongnam-si. The website (IP 220.73.161.119) is also hosted in the same country. Personally, I can not find anything in Internet pointing that STL is a legitimate and existing company.

I think we are well-known now with this rogue anti-spyware. If you know all the facts on MycomGuard, this will keep you safe from becoming a victim of this scam. And remember: always use a legitimate antivirus program that will protect your computer from threats like this.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Home > Latest Rogue AntiSpyware > A Final Look At MycomGuard Rogue