Most rogues do their dirty work by using an overwhelming number of detections (some, and maybe most, are false positives) to scare a novice into purchasing the rogue to remove what was either not there in the first place, or is trivial (like a tracking cookie or a missing help file).

Some like the one I am about to discuss, only showed a few…but those few strike terror in the mind of a novice.

The rogue programs on maxpcsecure (http://maxpcsecure.com/) cover the full spectrum of these “free scans”: “Max Spyware Detector”, “Max Registry Cleaner”, “Max RAM Optimizer”, and about eight more with the typical titles.

I was prompted to test some of these programs (using my VM and Sandboxie) because of a “review” made on the McAfee Site Advisor page (http://www.siteadvisor.com/sites/maxpcsecure.com/msgpage/showthread.php?p=3652575&posted=1) by a user with the screen name of “Rachnap”. I won’t quote the whole thing here, but it begins “Mywot.com is a hoax site having fake reviewers.” (For the full “review”, go to the link I just provided). That was enough to energize me to do my due diligence on this maxpcsecure.

Here are some of the things I found running these scans:

The following two screenshots display the completed scan. I ran SuperAntiSpyware, MalwareBytes, and Spybot S&D afterward. Other than the usual inconsequential tracking cookies, THE RESULTS OF THOSE SCANS DID NOT SHOW ANY TROJAN SPYWARE:


Here is where maxpcsecure is one of those that only show a few detections, but those few may scare novices into purchasing the removal program. My sense is that novices would be terrified by the use of the word “Trojan”, and consequently make the purchase. Notice also the descriptive paragraph on the left (it’s the same for both “Trojan.WebSearch”, and “Trojan.scar.pcp”.) It begins with “A destructive program”.

While that’s generally true of Trojans, if a novice reads that in conjunction with these bogus detections, they would likely get more terrified.

And, guess who can provide for removal of these Trojans? You got it!:

I also ran the “Max Registry Cleaner” scan:

This is a more typical rogue with hundreds of detections. If I had 1431 “invalid entries”, most of them shown as “high risk”, the machine wouldn’t even boot. Granted, there can be a high number of TRIVIAL “invalid entries”, but this beast shows most of them as high risk.

I would award maxpcsecure a blue ribbon in the “Rogue Hall of Shame“.

Finally, this Rachnap person, in a “review” post on SA (http://www.siteadvisor.com/sites/maxpcsecure.com/msgpage?page=3#reviews), made this remark:

“we invite our critics to prove us wrong and we will give a free copy of our product”

I would claim my “free copy”, but I don’t want any crapware/scareware/rogue on my machine.