Computer Repair Tips for everyday users

Before you attempt to do anything mentioned here or elsewhere, please remember to always back up your data.

ALL CONTENT ON THIS WEB SITE IS PROVIDED TO YOU ON AN "AS IS" "AS AVAILABLE" BASIS WITHOUT WARRANTY OF ANY KIND EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT.

Call (863) 521-1079

Showing posts with label scareware. Show all posts
Showing posts with label scareware. Show all posts

Friday, January 15, 2010

PC Security "Scareware"

The latest security scares going around are these rogue anti-spyware programs with names like PC Security 2009. Some of them look just like Microsoft Windows Security Center and people freak out and fall for it as it creates numerous fake infections using your file names on your computer.

These alerts are:

Trojan Detected!
A piece of malicious code was found in your system which can replicate itself if no action is taken. Click here to have your system cleaned by PC Security 2009.Privacy is at risk!
Attention, keylogging and intercepting scripts were detected. Your private data may be disclosed to third parties. Click here and PC Security 2009 will remove the infection.Privacy alert!
Your system was found to be infected with intercepting programs. These can log your activity and damage your privacy. Click here for PC Security 2009 spyware removal.

If you click on these alerts, you will then be prompted to purchase the program in order to fix these problems. DON'T DO THIS! This is a scam. Don't be tricked into purchasing their program.

It will also create a fake Windows Security Center and hijack Internet Explorer. Some will pop up with porn.com

PC Security uses deceptive tactics and convinces you that you are infected and in order to removed such infections you must purchase the full version of the software to do so. This is a nothing more than extortion. Though I don't know of anyone who has actually purchased this program, rogues like this are most likely a door to stealing your identity. I have read that purchasing does not necessarly does not actually help or is useful. In fact, because you gave credit card information you are now exposed to identity theft.

If you come across any of these rogue programs get out quick and don't click on a thing. You may have to manually remove this program but running combofix is the best way I have found. I go in and remove any traces and clear all temp files, history and cookies.

Virus Removal, Spyware Removal, Malware Removal

Computer Repair Lakeland, FL
863-521-1079
      

Wednesday, July 29, 2009

FAKE AV SOFTWARE EXTORTION

Fake Anti-Virus stops programs, making you buy their program to remove their malware.

This has been going on for some time and it is getting worse. I have had this happen to a many of my client and have ran into this breed just recently. I had to use Microsoft's MRT to scan and give me a hand and prc viewer to kill the processes as they came to play. I also used AVG's old root kit remover that is no longer available BEFORE I could INSTALL or RUN any other software such as Malware Bytes, Spybot and other programs as well. I couldn't even completely kill it in safemode. I would removed the files manually but they would reduplicate themselves. I found that with these types of infections, if you do a search for all files, including hidden and system files by date modified it is so much quicker. The last one I removed was so nasty I couldn't even run ComboFix on it, until followed through on the above.

Read what TrendLabs has to say below.

Taken from Malware Blog
Posted Jul26 2009
Rogue Antivirus Terminates EXE Files
9:02 pm (UTC-7) by Erika Mendoza (Threat Response Engineer)
This weekend, we at TrendLabs came across a FAKEAV variant similar to the one peddled in the solar eclipse 2009 in America attack in this recent blog post. This one, however, introduces another new scare tactic (so far the latest new ploy we’ve seen is the ransomware/FAKEAV that encrypts files in the infected computer and offers a bogus fixtool for a price).
This FAKEAV variant terminates any executed file with an .EXE file extension and displays a pop-up message saying that the .EXE file is infected and cannot execute.


This way, users are left with no choice but to activate the antivirus product since no other application works. This Trojan is detected by Trend Micro as TROJ_FAKEAV.B. It avoids terminating critical processes to prevent system crashes.
Unfortunately, cybercriminals work hard in creating so many gimmicks, that we can only guess what comes next in FAKEAV. Fortunately though, the Trend Micro Smart Protection Network provides users protection from such threats.Read more: http://blog.trendmicro.com/rogue-antivirus-terminates-exe-files/#ixzz0MfvDHv92

Contact a professional to help you:
Computer Repair Lakeland, FL
863-521-1079