What's this?

Irregularly posted tips, gleaned from all over the internet, for beginning and medium level computer and technology users. Feel free to subscribe to get these by email if you wish (below, right). Or,come to this site anytime. We update it about twice a month with new tips and links.
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Saturday, July 16, 2011

LONG but Important: Bad Guys Strike Again!



Watch out for a rise in fake desktop utility malware. These “bad guys” are fake windows recovery tools and are making the rounds through “drive-by downloads.”

Drive-by downloads may happen when visiting a website, viewing an e-mail message or by clicking on a deceptive pop-up window in the mistaken belief that, for instance, an error report from the computer itself is being acknowledged, or that an innocuous advertisement pop-up is being dismissed.

This new variant employs some new tactics such as disabling the task manager, hiding user programs and files by modifying file attributes, hiding start menu items and disabling multiple operating system features.
As seen in the past with other fake utilities, it attempts to scare the user with fake errors and tries to convince the user to buy the product in order to fix those errors. It uses a fake icon and file name to masquerade as a legitimate file as seen below:

Here are some screenshots of the fake utility in action:


It generates fake warnings:



It simulates a scan and displays fake error messages:


If the user proceeds to buy the advanced module it displays the following screen asking for credit card and personal information:



WHAT SHOULD YOU DO???


  1. Keep your anti virus up to date and RUN IT.
  2. If you think you might be infected, download and run Malwarebytes (www.malwarebytes.com) and Spybot Search and Destroy ( http://www.safer-networking.org/en/index.html)
  3. NEVER offer your personal information unless YOU have initiated the order (i.e. you are initiating an order from a legitimate website.)
  4. If you think you got scammed, contact your credit card company and bank immediately.

No comments:

Post a Comment

Please comment ON TOPIC only. Comments are reviewed before publishing and are deleted if I deem them inappropriate. Thanks.