Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New Fake Antivirus Attack Holds Victim's System Hostage
DarkReading ^ | Oct 15, 2009 | 02:42 PM | Kelly Jackson Higgins

Posted on 10/16/2009 7:14:08 AM PDT by knittnmom

Attack forces user to purchase phony antivirus package to free computer

(Excerpt) Read more at darkreading.com ...


TOPICS: Miscellaneous
KEYWORDS: malware; rogueware; virus
Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last
Provides details and countermeasures for an aggressive security threat. Not sure of posting/excerpting rules for this site, so erring on the cautious side.
1 posted on 10/16/2009 7:14:11 AM PDT by knittnmom
[ Post Reply | Private Reply | View Replies]

To: knittnmom
Better Link
2 posted on 10/16/2009 7:16:41 AM PDT by InterceptPoint
[ Post Reply | Private Reply | To 1 | View Replies]

To: knittnmom

Which story at that link are you referencing?


3 posted on 10/16/2009 7:16:58 AM PDT by La Lydia
[ Post Reply | Private Reply | To 1 | View Replies]

To: La Lydia
Which story at that link are you referencing?

See the link in Post #2.

4 posted on 10/16/2009 7:19:49 AM PDT by InterceptPoint
[ Post Reply | Private Reply | To 3 | View Replies]

To: knittnmom
I've encountered two machines with this....it's a nasty, nasty rootkit/boot-sector virus.

It goes so far as to disable booting in safe mode and it completely takes over the Windows shell.

5 posted on 10/16/2009 7:21:15 AM PDT by Psycho_Bunny (ALSO SPRACH ZEROTHUSTRA)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knittnmom

I hope we see an
Ad-Aware/MalwareBytes/Spybot/HijackThis type solution to this one soon. I do “Tech Support” for 4 grandsons age 5-11 so I’m dealing with this sort of thing all the time.


6 posted on 10/16/2009 7:22:41 AM PDT by InterceptPoint
[ Post Reply | Private Reply | To 1 | View Replies]

To: InterceptPoint

Thanks. I thought I pasted the full link, but must have missed some.


7 posted on 10/16/2009 7:24:27 AM PDT by knittnmom ("...only dead fish 'go with the flow'". - Sarah Palin 7/09)
[ Post Reply | Private Reply | To 2 | View Replies]

To: InterceptPoint

Okay, being a Mac person, I don’t understand this entirely. What company is responsible for this, and why can’t that company be held accountable? Are they overseas? Why can’t people put a stop pay on their blackmail payment to these thieves?


8 posted on 10/16/2009 7:27:25 AM PDT by La Lydia
[ Post Reply | Private Reply | To 2 | View Replies]

To: InterceptPoint

The link in the article to PandaLabs is invalid, correct link is http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx

And has a list of valid serial numbers to disable the attacking software.


9 posted on 10/16/2009 7:29:38 AM PDT by knittnmom ("...only dead fish 'go with the flow'". - Sarah Palin 7/09)
[ Post Reply | Private Reply | To 6 | View Replies]

To: hiredhand; Ernest_at_the_Beach

Ping


10 posted on 10/16/2009 7:30:20 AM PDT by Squantos (Be polite. Be professional. But have a plan to kill everyone you meet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knittnmom

A couple of weeks ago my screen went blank then up comes one showing what looked like the My Computer screen, it showed flashing red triangles telling me that it was under a virus attack and to click something to stop it.

I didn’t do it, of course.

I X’ed the window and did a virus scan. It found nothing.


11 posted on 10/16/2009 7:30:47 AM PDT by GeronL
[ Post Reply | Private Reply | To 1 | View Replies]

To: Psycho_Bunny

See #11.

Have you heard of this before?


12 posted on 10/16/2009 7:31:35 AM PDT by GeronL
[ Post Reply | Private Reply | To 5 | View Replies]

To: knittnmom
Can't vouch for this
13 posted on 10/16/2009 7:33:30 AM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: GeronL

Same/similar thing happened to me. The bogus screen made it look as if it had come from Microsoft. And at first, the warning didn’t want to close. IIRC, I just rebooted and did a scan; nothing came of it, thank goodness.


14 posted on 10/16/2009 7:35:10 AM PDT by Daffynition (What's all this about hellfire and Dalmatians?)
[ Post Reply | Private Reply | To 11 | View Replies]

To: knittnmom

And I can’t download Adobe 10 so I no longer can watch Youtube videos. It says I am running a 64 bit browser and Adobe 10 only works on 32 bit browsers. Anybody have any solutions?


15 posted on 10/16/2009 7:38:59 AM PDT by csmusaret (Obama. The master of Jack, Squat, and the Nobel committee.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: InterceptPoint
"I hope we see an Ad-Aware/MalwareBytes/Spybot/HijackThis type solution to this one soon. I do “Tech Support” for 4 grandsons age 5-11 so I’m dealing with this sort of thing all the time."

Practically all of the computer viruses "in the wild" are designed to attack Windows exclusively. Why wear a such a big target on your chest? I surf the web using an operating system whose environment is alien and immune to those Windows-oriented viruses: Linux. No worries. You don't even use an AntiVirus program, although you could download a free one if it made you feel any safer. Your grandsons would find Linux just as easy to use as Windows, and probably easier. It is easier to install, too. I recommend Ubuntu or Linux Mint. All free, too.

16 posted on 10/16/2009 7:42:38 AM PDT by TexasRepublic (Socialism is a parasite that kills the host)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Psycho_Bunny

I’ve been a victim of this one. Got past Norton.


17 posted on 10/16/2009 7:42:55 AM PDT by DManA
[ Post Reply | Private Reply | To 5 | View Replies]

To: La Lydia

I deal with these all the time with my work and I call them “extortion ware”. The companies look like they are based out of Russia, and unlike traditional viruses, it is not about bragging rights, it’s about cold hard cash.

These programs are designed to look legitimate, even going so far as scanning your system to find out what anti-virus you are using and modifying the “warning screen” to match it. I’ve seen screens that look like it came from Microsoft, Norton, McAfee, AVG, Avast and Panda.

They make money because many people assume that it came from their company and they need this new program from that company to clean off the viruses.

When people run their anti-virus or anti-spyware program, these nasty little pieces of extortion-ware unleash their trojans and infect the system something fierce.

Malware-bytes and Spybot S&D have been lifesavers for me and my clients when they get hit hard.

An FYI to Mac users who care. One of the Russian groups has put out a bounty contest on anyone who can infect a large group of Macs with a trojan and get verified reports back from the machines. Every Mac who sends a report back earns the creator of the virus 40 cents. This sounds like someone is finally going to go after the growing Mac user base. So be careful what you click on out in cyberspace.


18 posted on 10/16/2009 7:48:06 AM PDT by Anitius Severinus Boethius
[ Post Reply | Private Reply | To 8 | View Replies]

To: GeronL

I try to run scans every night (when I remember), I launch MalwareBytes one night, and McAfee the next. So far, so good.


19 posted on 10/16/2009 7:53:40 AM PDT by knittnmom ("...only dead fish 'go with the flow'". - Sarah Palin 7/09)
[ Post Reply | Private Reply | To 11 | View Replies]

To: csmusaret
And I can’t download Adobe 10 so I no longer can watch Youtube videos. It says I am running a 64 bit browser and Adobe 10 only works on 32 bit browsers. Anybody have any solutions?

there is no solution. Adobe has idiots working for them. No 64-bit Flash. No Flash for iPhone. Morons.

20 posted on 10/16/2009 8:01:37 AM PDT by montag813 (During times of universal deceit, telling the truth becomes a revolutionary act. -George Orwell)
[ Post Reply | Private Reply | To 15 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson