Results 1 to 10 of 86

Thread: Rogue AV/AS prolific

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Thumbs down Scareware fakes HD failures ...

    FYI...

    Scareware fakes HD failures...
    - http://www.symantec.com/connect/fr/b...efragger-sales
    16 May 2011 - "... Hard disk failures are a fact of life... Trojan.FakeAV writers are aware of this, and the end of last year saw a move by some into the creation of fake hard disk scanners and defragmentation tools... Trojan.Fakefrag. What sets this apart from standard fake disk cleanup utilities is that the Trojan makes changes on the computer and displays messages that make it appear as though the hard disk is failing. Then it drops a member of the UltraDefragger family called Windows Recovery, which offers to repair these disk errors for a mere $79.50!...
    • It fakes hardware failure messages...
    • It moves all the files in the "All Users" folder to a temporary location and hides files in the "Current User" folder. This makes it look like you have lost all the files on your desktop.
    • It stops you from changing your background image.
    • It disables the Task Manager.
    • It sets both the “HideIcons” and “Superhidden” registry entries to give the impression that more icons have been deleted.
    ... the failure messages look just like something Windows would display..."
    (Screenshots, video, and more detail available at the Symantec URL above.)
    ___

    New scareware - charted
    - http://blogs.mcafee.com/wp-content/u...G_110513_2.jpg
    May 13, 2011

    Last edited by AplusWebMaster; 2011-05-18 at 16:42.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #2
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Thumbs down Fake AV bingo - 165 domains of bad

    FYI...

    Fake AV bingo - 165 domains of bad
    - http://isc.sans.org/diary.html?storyid=10894
    Last Updated: 2011-05-19 00:06:54 UTC ...(Version: 2) - "Can you guess which domains the crooks behind the Fake Anti-Virus Scam are going to use next ? Well, neither can we. But for several weeks now, they are hosting a lot of their bad stuff out of 91.213.29.66, geo-located in... Russia... all in all 165 domains of badness.
    Several of these domains were "found" by our readers via the poisoned Google image searches* that we reported earlier this month, and also via malicious advertisements embedded in perfectly benign web pages...
    Fake AV has made its appearance on Macs**, where naive automatic download-and-run default settings in browsers still are common, and where "MacDefender" and its expected numerous successors and variants are likely to become as "successful" for the bad guys as their Windows version has been for years..."
    * http://isc.sans.edu/diary.html?storyid=10822
    2011-05-04
    ** http://isc.sans.edu/diary.html?storyid=10813
    2011-05-02

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #3
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Thumbs down Mac Fake AV...

    FYI...

    Mac Fake AV...
    - http://news.cnet.com/8301-27080_3-20064394-245.html
    May 19, 2011 - "Macintosh users are being targeted with malware that poses as an antivirus warning and tries to trick people into paying for software they don't need. This ruse isn't new. So-called rogue antivirus has been hitting Windows machines for years. But this is the first time this type of malware has been written to target the much smaller Mac market... Mac Defender, also known as Mac Security and Mac Protector, is a fake antivirus program that is designed to scare people into thinking that their computers are infected with malware..."

    - http://blog.intego.com/2011/05/02/in...ake-antivirus/

    - http://download.cnet.com/8301-2007_4-20064445-12.html
    May 19, 2011 - "... On any platform, rogue antivirus programs are resistant to standard program removal procedures. This means you can't just drag one to the trash..."
    (More detail on removal procedures at the above URL.)
    ___

    - http://www.h-online.com/security/new...e-1246693.html
    20 May 2011 - "... Users of the Safari web browser should disable automatic file opening in Safari (Preferences -> General and uncheck "Open 'safe' files after downloading"). More importantly though, users should, when prompted for their user name and password, be asking themselves "what is requesting this information" and remembering that they are giving it privileges to modify their system..."

    Last edited by AplusWebMaster; 2011-05-20 at 19:23.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  4. #4
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Post Apple advisory on MacDefender malware

    FYI...

    Apple advisory on "MacDefender" malware
    - http://isc.sans.edu/diary.html?storyid=10918
    Last Updated: 2011-05-25 00:05:17 UTC

    - http://support.apple.com/kb/HT4650
    May 24, 2011 - "... Products Affected:
    Mac OS X 10.4, Mac OS X 10.6, Mac OS X 10.5..."

    Safari "Force Quit"
    - http://support.apple.com/kb/ht3411

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •