multiple references, and do a bit of digging on the manufacturer's website... something that looks a bit too 'web 2.0' may throw up a flag, generally a sign of a hastily built site (in a hurry for a reason!), companies that only sell one product are also a good example of a red flag... one more thing to keep in mind, if a website EVER tells you 'you're infected! look at these viruses! click here to fix it!' it's ALWAYS a scam. also pay attention to any site that references your registry or registry errors- generally a scam... even if they're legit, registry 'cleaners' cause more harm than good.
also, you can ask on here or ask a trusted IT professional... a number of us have worked in IT and are willing to help (chocucove also comes to mind, he's a pretty sharp dude... same with signburst.) if it helps, i've worked in the antivirus/antimalware industry on products for home and corporate (windows/linux).
the sites I just sent are legitimate, including one from the writer of vipre (Sunbelt Software/GFI). cnet/pc magazine reviews are also helpful as they test software before reviewing it.