ScanSafe, a company that provides malware scanning for large companies, tracked banner ads served from the popular website for more than 72 hours. The ads use a modus operandithat's all too common: They present visitors with a popup masquerading as a Windows dialog box that informs them their machine has been struck by spyware and offers a rogue anti-virus program that supposedly will fix the problem.Now you should be very suspicious any time you're browsing some random web site and you see a popup saying "d00d! Ur's like totally pwn3d! I gotz a free antivirus 4u!!!1!" Like this:
There are good, free antivirus scanners available, from reputable companies. Here are some that I recommend. Tell 'em Borepatch sent you, for an extra 10% off the low, low price of free.
Trend Micro House Call. You need Internet Explorer for this.There are free downloadable antivirus scanners, too. Instead of running these in your browser, you install them and run them on your computer. I recommend all of these.
Eset Online Antivirus Scan. Probably need IE for this, too.
F-Secure Online Antivirus Scanner.
Kaspersky Free Virus Scanner.
Panda ActiveScan.
AVG Virus Scanner. We use this here Chez Borepatch, on the Windows machines.So there's no reason to go to the local bootlegger for your free antivirus needs.
Avast! Home Edition.
Clam Antivirus. It's a bit more manual (it identifies malware, but you need to delete it). But it's Open Source.
So the trojan this popup installs, how do you get rid of it? I got a user's machine, I think it's clean and then the next day it's back.
ReplyDeleteThanks for the info Ted. I think I am gonna try AVG on my home machines.
ReplyDeleteOn another note, I love the text from that fake popup. "The spyware". Is that kind of like "The Walmarts"? It might also be a good idea to spell correctly, when trying to scam someone into believing you are legit.
/giggle