{"id":3119,"date":"2010-04-28T08:09:47","date_gmt":"2010-04-28T12:09:47","guid":{"rendered":"http:\/\/www.schollnick.net\/wordpress\/?p=3119"},"modified":"2010-04-28T08:09:47","modified_gmt":"2010-04-28T12:09:47","slug":"google-fake-antivirus-is-15-percent-of-all-malwarekn","status":"publish","type":"post","link":"http:\/\/www.schollnick.net\/wordpress\/2010\/04\/google-fake-antivirus-is-15-percent-of-all-malwarekn\/","title":{"rendered":"Google: Fake antivirus is 15 percent of all malwareKn"},"content":{"rendered":"<p>According to a Google study, 15% of all malware consists of <strong>fake anti-virus <\/strong>(or Rogue Antivirus) software. \u00c2\u00a0What does that mean to the average user, probably nothing, but are you sure that Antivirus warning you just received is really from your antivirus software?<\/p>\n<p>Practically, this means that you need to be more aware of your antivirus software:<\/p>\n<ul>\n<li>Know the name of your antivirus software<\/li>\n<li>Make sure that your subscription is up to date, and that updates are occuring for both the Antivirus &#8220;engine&#8221; and the &#8220;definitions&#8221; file. \u00c2\u00a0The Engine is the software itself, the definitions are what identify a virus to the engine. \u00c2\u00a0So if your subscription expires you may still see engine updates, but your &#8220;play book&#8221; will be out of date and your software won&#8217;t recognize newer viruses.<\/li>\n<li>If you receive a virus warning, make sure that pop up window refers to your antivirus software. \u00c2\u00a0For example, if you run Sophos&#8217;s antivirus product, and you see a warning from &#8220;Windows 2010 Antivirus Defense&#8221;, chances are it&#8217;s a fake warning. \u00c2\u00a0(Please note, you may also have &#8220;Windows Defender&#8221; running, that&#8217;s a anti-malware package from Windows).<\/li>\n<li>If you see a valid warning, close all your applications, especially web browsers. \u00c2\u00a0Don&#8217;t download anything, and run your antivirus software with a full scan&#8230; \u00c2\u00a0If it detects anything attempt to clean it.<\/li>\n<li>If you become infected, try running the <a href=\"http:\/\/securitytango.com\/\">Security Tango<\/a>.<\/li>\n<li>Why all this work?<br \/>\n<span style=\"font-family: Arial, Helvetica, sans-serif; line-height: 17px; font-size: 12px; color: #353535;\"><br \/>\nMore recent fake AV sites have evolved to use complex JavaScript to mimic the look and feel of the Windows user interface,&#8221; the report continues. &#8220;In some cases, the fake AV detects even the operating system version running on the target machine and adjusts its interface to match.&#8221;<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: Arial, Helvetica, sans-serif; line-height: normal; color: #353535; font-size: 12px;\"><\/p>\n<blockquote>\n<p style=\"margin-top: 15px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; text-align: left; vertical-align: baseline; line-height: 17px; padding: 0px; border: 0px initial initial;\">Fake antivirus is easy money for scammers, Provos said.<\/p>\n<p style=\"margin-top: 15px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; text-align: left; vertical-align: baseline; line-height: 17px; padding: 0px; border: 0px initial initial;\">&#8220;Once it is installed on the user system, it&#8217;s difficult to uninstall, you can&#8217;t run Windows updates anymore or install other antivirus products, and you must install the [operating] system,&#8221; rending it unusable until it is cleaned up, he said.<\/p>\n<p style=\"margin-top: 15px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; text-align: left; vertical-align: baseline; line-height: 17px; padding: 0px; border: 0px initial initial;\">Provos said when encountering a fake antivirus message, Web surfers should close the browser and restart the program. People who are duped by the scam may have to get professional help in cleaning up the computer, he said. They should also monitor their credit card accounts because scammers can use the credit card information for identity fraud.<\/p>\n<\/blockquote>\n<p><\/span><\/p>\n<ul>\n<li>Check the reputation of the antivirus packages that you are running, there are smaller companies that make antivirus packages that are not dependable. \u00c2\u00a0Consider using AVG, Avast!, eTrust, and Panda Software&#8217;s Antivirus 201x for Antivirus. \u00c2\u00a0For Antimalware, SuperAntispyware, Malwarebytes, and Windows Defender. \u00c2\u00a0If your software is not on this list, please check reviews on cnet.com, or another trusted source.<\/li>\n<\/ul>\n<p>Check out\u00c2\u00a0<a href=\"http:\/\/news.cnet.com\/8301-27080_3-20003340-245.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20\">Google: Fake antivirus is 15 percent of all malware <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to a Google study, 15% of all malware consists of fake anti-virus (or Rogue Antivirus) software. \u00c2\u00a0What does that mean to the average user, probably nothing, but are you sure that Antivirus warning you just received is really from your antivirus software? Practically, this means that you need to be more aware of your <a class=\"read-more\" href=\"http:\/\/www.schollnick.net\/wordpress\/2010\/04\/google-fake-antivirus-is-15-percent-of-all-malwarekn\/\">[&hellip;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[12,25,35,11],"tags":[248,121,115,202,91,1838,154,31,212,119],"_links":{"self":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts\/3119"}],"collection":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/comments?post=3119"}],"version-history":[{"count":0,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts\/3119\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/media?parent=3119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/categories?post=3119"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/tags?post=3119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- WP Super Cache is installed but broken. The constant WPCACHEHOME must be set in the file wp-config.php and point at the WP Super Cache plugin directory. -->