Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in antivirus (53)

Saturday
Jul112009

Scareware Adviser from securitybrowseradviser.com

It looks like I have been added to this website but it is a fake URL Hijacker that wants to sponsor [intlink id="3607" type="post"]Personal Antivirus Just Scareware[/intlink]. Yep you guessed it they are blocking this url from trying to be displayed some of the people are still ignoring the warning and coming to my site  anyways.
securitybrowseradviser1

So the first question is how do I know this is a fake site warning. Well I did my research I went to Phishtank.com and check to see if my URL was being blocked. I also clicked the link to see what this link went “Activate my Web protection software”. It sent me to this site:

personalantivirus2

[ad]As you can see this site “ieprotectionlist.com” calls itself the [intlink id="3607" type="post"]Personal Antivirus[/intlink] and look it even says “Malicious behavior detected”. I start looking for anything about this software no links to contact them or no links to learn more about this product. This is how I know this is a scareware site. If you seem to be getting these warnings it is time to go download[intlink id="2205" type="page"] real antivirus software[/intlink].

[ad]As you can see the Securitybrowseradviser.com is a scareware sponsor for the [intlink id="3607" type="post"]fake Personal Antivirus software[/intlink] that it is linking to. So if you getting this it is time to remove it.

I would Recommend SUPERAntivirus Pro although the Free version is good to remove this scareware or spyware. I have found it does find all the programs and where they are located. If you feel like you want to do it yourself be warned that is a cumbersome process and might hurt your system more than letting a program do it for you.

I will be doing a review of SUPERAntivirus Pro in the next few weeks, I do think it does the job plus more. When I do a scan with this product it actually finds more than expected.
Monday
Jun292009

A-Squared Emergency USB Stick - Portable Antivirus Kit



[gallery link="file" order="DESC" columns="2"]

IT Security warfare is an interesting domain. It is a never ending race between the security software developers and malware writers. And since the security software always act after the development of the malware, they are always behind in this race.

But this fact poses a serious threat to the security of your system as a user. If you are not careful and regularly updating your antivirus applications, you might be late, and if the malware might get a chance to get the entry to your system, it can play havoc there.

Today’s Intelligent Malware…


Today’s malware are much more intelligent than their predecessors. They not only do the damage intended by their developers, but also make it difficult for security software to identify them. They try to disable your antivirus applications, they modify your system files so that you are not able to access the security software websites and forums, they hijack your browser homepages, they disable the update procedure of your security software and use all such tricks, which make their detection difficult.

What is the Solution?


In a such a situation, you need a security tool, which remains aloof from your system and can be used as and when required. A-Squared Emergency USB Stick is one such portable tool, which can be used in such a situation.
A-Squared Emergency USB Stick is a combination of two free security tools from the reputed security vendor EMSI. These tools are…

A-squared Free:


[ad]With a-squared Free you have got the powerful a-squared Scanner including graphical user interface. Search the infected PC for Trojans, Spyware, Adware, Worms, Dialers, Keyloggers and other malign programs.

a-squared Command line Scanner:


This scanner contains the same functionality as a-squared Free but without a graphical user interface. The command line tool is made for professional users and can be used perfectly for batch jobs

You can download this and save it in your USB Flash Drive. In some unfortunate instance, when the security software installed in your system is not able to detect any malware, and the malware damages your system files, then there are chances that this USB stick remains protected, because it may not have been inserted in your computer at the time when the malware has been doing its job.

Once you are aware about the presence of the malware, you can try to use this portable antivirus kit to clean your system. The command line tool coming with this portable antivirus toolkit is especially useful because many of the present day malware can potentially disable the GUI interface of the popular security software.

[Download A-Squared Emergency USB Stick]

[This is a Guest Post from Silki Garg, who enjoys writing about Internet and PC Security Issues. Check out her latest articles on ClamWin Portable Virus Remover and Windows Security Options Tool WinPatrol.]

Wednesday
Jun242009

Insanity Run Rampant -- Antivirus Pro System (scareware)

Some of you would want to ask me why I am calling this title an usual title. In fact it is quite simple, I have been at the hospital since early this morning. While I was there I had some intriguing things happen. I was watching a person cruise the internet while they were at work. This is someone who is supposed to answer the phones and such. Then I see this POP UP, this draws my attention. "You SYSTEM Has Spyware". This was my first thought, Scareware. The Popup said it was for "Antivirus Pro System".
antivirus-system-pro

Since this was a Hospital computer, I couldn't get a real screen shot of this but there are plenty examples out there, just like that one above.  Anyways what worries me is how System Admins are allowing employees to surf the web while at work on company time.   It also makes for a bad experience with their family.  It also concerns me about the fact that while that computer is infected some of the patients records could be leaked online.

[ad]If you have this Scareware program, Here is a good explanation on how to remove it.   Hospitals have a duty to protect peoples privacy.   Although I seriously this system had patient records it was being used to keep track of who was in surgery and where they were.

Hospitals should prevent their employees from using the internet and preventing patients or their family's from using the internet.   While I was there I couldn't do much but check my email and Maybe watch Twitter using Tweetdeck.   That was how bad the bandwidth was there.  According to some nurses they have a T1 Line.   So you know people are watching movies or other things through the internet.   I also heard from a doctor that people were streaming who were supposed to be at work.

That has been my day,  and am I tired.

I would also suggest people have a f[intlink id="2205" type="page"]ree anti-virus software and a Good free Firewall[/intlink] to help prevent this type of scareware in the future.  Remember your the End User and that means only you can prevent this from happening in the first place.  Never go to suspicious sites or URLS that you don't know where they go.   If you can prevent these types of attacks then you are much better off.
Monday
Jun152009

Facebook games having Scareware redirect Sites

I was on Facebook Yesterday doing my usually just playing one of my games when all of the sudennly this pops out:

powerantiviruscannerv2scam



[ad]As you can see this seems to be another site which is a [intlink id="3397" type="post"]scareware site[/intlink], the site Powerantivirusscannerv2.com is trying to [intlink id="3607" type="post"]scare you into buying a fake antivirus.[/intlink]   I don't know if it was Facebook doing this or if I got the redirect cookie somewhere else.    Although if you have downloaded the program that they want you to install or even think you have this fake antivirus installed, Spywareremove has the information needed to remove off your system.  It seems they are going to use social sites more and more and you should be careful.  I also have some good resources like [intlink id="2205" type="page"]Free Anti-virus and Free firewalls[/intlink] that would help protect you from this threat.

Somethings to consider when you see something like this pop up are?  Do you have antivirus or a firewall?  If so, then you shouldn't be worried to much.   Always look to see if you can see if it is a webpage and not from the system.  This is something the scammers are always trying to do to get your money.  Remember these sites are not really a trustworthy site and should be avoided at all cost.  I also recommend using the[intlink id="2362" type="post"] Hijackthis software[/intlink] to look for these rogue softwares in your system to better protect your system.

Remember not everything is real or truthfull on the internet with proper research and understanding you won't be making those rash decisions.   Only you can prevent you system from being infected.
Friday
May222009

Personal Antivirus just scareware

I was going through checking a site brought to my attention from a reader and I went there and yep he told me it might be [intlink id="3114" type="post"]scareware[/intlink] and it was:

mailware-live-pro-scanv1-1

If you click "Cancel" or "Ok" you will still get to this page:

mailware-live-pro-scanv1-2


[ad]It is on the Malicious site : http://maleware-live-pro-scanv1.com.  You can also see it tries to scare you with the tactic of  knowing your IP address and where you are in the world, it's called Geo-ip Location.   It tries to convince you have a virus, but in reality it is just trying to scam you out of money.   Although if you go to the site you will see that there is no company information.  That is the first clue this is a scam or scareware.


Personal Antivirus gets installed in unsuspecting computers by way of exploits, backdoors, Trojans, or unsafe downloading practices.   This usually means that if you have it you should remove it by any means necessary because this software has been know to cause more and more trouble as time goes by.   This software is fake ware, it tries to tell you have a virus and that they can get rid of it.   In fact, this software is not designed with Antivirus engine in it but to illicit pop ups and warning to raise the users security concerns about the computer in question.   Downloading programs from bit torrents or other unsafe ways can and most likely will have these types of programs installed alongside the program you wanted.


*[intlink id="4403" type="post"]Personal Antivirus Scareware Site and How to Remove it[/intlink]*


Threat to System : Moderate



[rating:4/5]




Advice : Do a Complete system scan and make sure you don't have any more hidden malware. Most of the time if you have one Trojan, you usually have more.  Personal Antivirus has been know to have some type of program installed on the system in question and should be removed.



I recommend :

[ad#SUPERAntiSpyware]

On a side not, if you are wondering why I think I know I am not infected with these virus for those who are probably asking that question is because I already have a [intlink id="2205" type="page"]dependable free anti-virus[/intlink] software installed.  Don't forget to visit the Forums for other ways to watch for spyware or scareware.   I will always recommend buying antivirus software from vendors you know and not ones that are fly by the night scams.

Friday
Jan162009

How Serious is the Downadup.b/Conflicker Worm?

In there latest post F-secure has updated how many people are infect and I'll quote:
Today's calculation is a total of 8,976,038 infections worldwide and 353,495 unique IP addresses.

That's a quite a big difference compared to our last number — there will be a follow up post coming soon to explain the methodology.

[Via F-secure]

F-secure has noticed it went up from 3,521,230 infections worldwide. This Worm has doubled in over a day.  So I have done some twitter searching to see if anyone has recently tweeted about this and I find this one comment:
[ad#ad2-right]
WTF? suddenly my antivirus is popping with warnings about a W32.Downadup.B ... but I havent received any attachs or installed anything!

[Via Twitter Mklopez]

I'd thought I show you how important it is for you to get ready for a very hard fight ahead of yourselves.  You see this hasn't even begun with this worm.
Here's are some of the tweets:

2 customers, have this conflicker.worm problem and we are trying every possible solution but nothing turned out to be solved

[Via Twitter  Candegger]

@carnal0wnage Hey happy new year, what malware one of my clients just had a large outbreak of the conflicker virus, pretty good virus

[Via twitter MarcoFigueroa]

[ad#ad2-right]This worm doesn't need to be downloaded because it will use exploits that are currently unpatched in the systems .  This worm seems to be spreading by USB sticks and you should really turn that off. If you think you've gotten this virus, please check out my Malware Resources and also some of the other post about this worm:




I hope these resources help you fight that worm and help people get your system back to normal.

Check out my other Posts about Conflicker/Downadup Worm.
Friday
Dec192008

Virus Handbook -- 39.95$ Shows you the theory behind E-mail Virus.

Amazon reviews this book and says:

E-mail Virus Protection Handbook : Protect your E-mail from Viruses, Tojan Horses, and Mobile Code Attacks (Paperback)E-mail Virus Protection Handbook


The authors of this volume (and there are several) begin by explaining how and why e-mail viruses work--they point the finger mainly at software that's designed for slick presentation of mail instead of for security, as well as at uninformed end users. Then, they begin to explain what various countermeasures, including antivirus software and firewalls, can do, and offer specific configuration advice. They also explore means of configuring popular e-mail servers and clients for maximum resistance to viruses. Overall, this book is carefully researched and should provide system administrators with the information--both practical and background--that they need to protect their systems from some of the more insidious threats around. --David Wall

Price: $39.95

If your like me and your curious how these viruses work. This book is good for those who want to learn how to fight or combat viruses that usually come with E-mails. You have to know why there are viruses and why you need Anti-virus software. Although I've only read some of this, it makes my head spin. I'd recommend people read it at least twice. This is good for technicians who have to fight with viruses a lot, will give you so many good ideas on how to combat them.

Please visit my store for other Recommendations.  I'll update them when I find more cool stuff.
Monday
Dec152008

Tools for Virus Removal : The ones I like to use!

In this post I want to talk about virus removal tools that I like to use when I need to remove a virus.   Some thing to consider when using these tools are:

Each of these have to be dealt with differently because each requires something different.  Like rootkits if you have one installed and know that it is a rootkit you only options are to download some rootkit removers like:

  • Sopho's Anti-rootkit remover --  This is good for those more known viruses and can remove several types of rootkits.   This isn't the only one I use, but it is a part of group that does the rootkit removing for me.

  • Microsoft Rootkit Revealer --  This is good for proving there is a rootkit.  I've not seen it not detect a rootkit.  Most of the time when I find a rootkit from the other rootkit revealers this one actually dos better with information.

  • Panda Anti-Rootkit Remover -- This one is another one I use when the other ones can't remove it.  Each one does remove certain rootkit differently and works better than the other.

  • Aries Rootkit Remover from Lavasoft -- This is good for those really tough rootkits but have some great benefits for removing some of the really tough rootkits.


These are the ones that work well with me when it comes to removing the rootkits.  I've not had one of these to remove a rootkit but that depends on how you deal with the virus in the first place.  Now for Anti-spyware and Anti-Virus software here are some of the tools that I suggest:

  • Hijackthis -- Run it, and when you get the LOG file you will want to go to HijackThis Log Analysis Site 1 and HijackThis Log Analysis Site 2, and see what it says.  This is the best software because it will scan all of the registry and tells you like a wiki what might it be.

  • MSCONFIG -- Sometimes it is hidden but if you check through the MSCONFIG for any files that might not need to load. Also check the services tab and see if there is any services that may not be needed.

  • Pctools Antivirus Free Software -- This is a free software so what can I say.

  • AVG Anti-Virus Free Edition 7.5.503 -- This is another free one that can remove viruses really easily. Download this and you don't have to worry to much.

  • Avast Home Edition -- AVG does better than this one but people seem to like this so I have to add this for people who like this better than the others.

  • Clamwin Free Anti-virus -- This is a good one because this is open sourced and easily can help detect so many viruses. This is good for those people who like open sourced.


These are just  the ones that I like to recommend that does pretty good on removing the viruses but there are others that I recommend on my Malware Resources that people have recommend to me but I haven't tried them out yet.    Some of the Spyware and Adware removal and here are some of my favorites:

  • SuperAntispyware -- Easily remove pests such as WinFixer, SpyAxe, SpyFalcon, and thousands more! Repair broken Internet Connections, Desktops, Registry Editing and more with our unique Repair System.

  • Malwarebytes can provide the needed assistance to remove the infection and restore the machine back to optimum performance.

  • Ad-Aware — This is a very good tool to get rid of some of the most annoying little viruses that try to fool you that you have a virus.

  • Windows Security Trojan Scanner — a Free online scanner to let you see if you might have a Trojan.

  • SmitFraudFix — A great little program to get rid of those Desktop hijacks, those programs that take over your browser or other file system.


If your current antimalware software let an infection through, you may want to consider purchasing the PRO version of SUPERAntiSpyware or Malwarebytes License to protect your computer in the future. SUPERAntiSpyware Professional or Malwarebytes License features highly advanced Real-Time Protection to ensure protection from installation or re-installation of potential threats as you surf the Internet (Both are trusted Vendors by CCSS Forums).

These are just a few that I like to use when it comes to fighting those virus programs and the people behind the virus programs.   If you consider how hard it is sometimes to recognize a virus, you can see the problem with some of the programs they can sometimes  say a file is a virus and delete it and the next thing you know it won't boot into Windows.  This is what needs to be considered whenever you see a warning on your system so you must be careful when you remove files.  You should always have backups that is what I always recommend because the likely hood of something terrible happening to your data.  You should come up with a way to back up your system every week like a sunday back or even a Monday while your at work backup.
Friday
Dec052008

Trojan.PWS.ChromeInject.A is not a Firefox plugin.

A new type of malware designed to harvest web passwords has been detected in-the-wild by BitDefender’s antivirus research labs. This latest e-threat – called Trojan.PWS.ChromeInject.A – is intended to be delivered onto a compromised computer system by other malware for subsequent download into Mozilla Firefox's Plugin folder. Once installed it gets to work every time Firefox is started.

[Via Bitdefender]

[ad#ad2-right]So having seen this I thought I'd come up with ways around this to better protect yourself.  One way to prevent this from getting your sensitive data is to get a program like Sandboxie.   You could stop using Firefox that would be silly, because right now Firefox is more secure than Chrome and Internet Explorer.   I'd also suggest checking out my Anti-spyware page and Anti-Virus page and get some more protection.

The key to this virus protection is just be cautious of where you go and keep all you system update to date to prevent all this from happening.  It is also advisable to not have your passwords saved on Firefox, you should use something like Roboform, it is free  to download and try.  It will encrypt your passwords so if they don't know the master password then they are out of luck.  Roboform is also good for coming up with some strong passwords.  Just some suggestions to prevent from people seeing your sensitive data, you don't want anyone to get that data.
Friday
Nov282008

Not so, Antivirus2008

[ad#ad2-left]On F-secure blog they talk about this rogue antispyware.
OK, so let's say the user (by some stroke of luckless chance, or courtesy of a trojan downloader) ends up with the demo installer of Rogue:W32/VirusRemover2008.C on their hands and it runs
[via F-Secure]

According to them, they have many different version of this rogue antispyware.  They have de, dk, es, fr, it, no, nl, and no, which are all attempting for you to buy this no so Virusremover2008 software.  They talk about how it tells you have a 9 infected viruses and that you need to remove them, but in truth, they use a text file to create this lie.  Check out all the details for further information.
Tuesday
Nov252008

Microsoft kills a fake antivirus tool from 994,061 computers!

According to Arstechnica and I'll quote:

[ad#ad2-left]Win32/FakeSecSen has gone by various names, including Micro Antivirus 2009, MS Antivirus, Spyware Preventer, Vista Antivirus 2008, Advanced Antivirus, System Antivirus 2008, Ultimate Antivirus 2008, Windows Antivirus, XPert Antivirus, Power Antivirus, and Ultra Antivirus 2009. Furthermore, it is skinnable, so each of these variants has a different GUI, although the basic functionality is the same: bother users with warnings of malware until they pay up.

The Microsoft Malware Protection Center recently released some data on how the removal tool performed this month: FakeSecSen was removed from 994,061 machines. That number isn't the highest Microsoft has recorded before, and the number of removals depends on which malware Microsoft adds each month and how widespread it is.

[via Arstechnica]

This seemed to of happened this month with the usual Windows update.  If you haven't updated your system just yet you should.   This troublesome fake virus seems to have been killed  from several systems.  This could effectively make it harder for these guys who ever designed this program to make money.  I hope microsoft does even more virus removals in next month.  If you still want to try to get rid of these viruses don't forget to check out my tips on Virus removal.
Thursday
Nov202008

Vista has a new Vulnebility!

According to Techworld.com,  Vista has a new Vulnerability that could let a hacker infect a Vista machine with a rootkit.  The talk from them is quite intriguing.   I will quote it to better let you know what the Vulnerability is:
The vulnerability could allow a hacker to install a rootkit, a small piece of malicious software that is very difficult to detect and remove from a computer, Unterleitner said.

[ad#ad2-left]Phion notified Microsoft about the problem on 22 October. Microsoft indicated to Phion that it would issue a patch with Vista's next service pack. Microsoft released a beta version of Vista's second service pack to testers last month. Vista's Service Pack 2 is due for release by June 2009.
[via Techworld.com]

The way they could do this is through the Device IO Control which in turn could corrupt the Kernel of Windows Vista.  Now we all know that Microsoft will release a patch quicker than 6 months away.  According to this article, people are already looking for the exploit and want to know more about it.  I would be willing to bet they will have a patch out sooner than later.  Probably January or Febuary, which will be a big deal because no one will expect it.  I would also imagine hackers will start trying to figure out how they could install software as quick as possible before Microsoft pushes out the patch.   So what can you do to protect yourself, Get a firewall, a Antivirus and learn how to protect yourself to prevent yourself from getting a computer virus.
Monday
Nov102008

Antivirus Professional 2008 uses Scare tactics

[ad#ad2-right-1]
We came across a rogue today called Antivirus Professional 2008 that uses GeoIP Lookup as part of its scare tactics. This site uses Flash and script to create the effect of an online scan, that then attempts to push an installer at the visitor. The NoScript extension for Mozilla Firefox is an excellent way to mitigate against this kind of garbage.

[Via F-secure]



It seems that there is a site out there, that seems to be trying to scare you into downloading there software. If you have any questions about this site please feel free to check out what I've found out:
Registration Service Provided By: ESTDOMAINS INC
Contact: 1.3027224217
Website: http://www.estdomains.com
Domain Name: ANTIVIRUS-ONLINE-SCANNER.COM
Registrant:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Creation Date: 07-Jun-2008
Expiration Date: 07-Jun-2009
Domain servers in listed order:
ns2.antivirus-online-scanner.com
ns1.antivirus-online-scanner.com
Administrative Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Technical Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Billing Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732



[ad#ad2-right]Now as you can see this site is located in Russia, and if that's the case it is probably some virus itself to take control of your system to do what they want with it. So you best advice is if you think you have a virus then check out my recommendations these are all free to download and try. Unlike this site, they are legitimate and actually do what they promise.  If you want to email them you can but It don't think it will help.

*UPDATE on that Website*


According to F-secure that site is now Suspended.  Great job guys.  We are now fighting these people even better than I'd thought.
Page 1 2 3