Archive for December 28th, 2011

Downloading viruses masquerading as security software

December 28th, 2011 by pam
Filed in Blog | Comments Off

One of the latest scare-ware viruses out there is called XP Security 2012 or Vista Security 2012 or Win7 Security 2012 depending on what operating system you are using.  If you haven't seen this one, you probably will.  Hopefully you will know it is bogus and will sever your connection to the internet immediate--unfortunately, it may already be too late.

It is really hard to tell our customers that the reason they have a virus, even though they have Vipre and Malwarebytes installed on their machine and update and use them religiously, is that they themselves downloaded the virus and installed it, not realizing what they were doing.

It always feels like blaming the victim or like we're making excuses for why our recommended anti-virus program didn't protect them.

Though most users can pretty much tell us what happened just before their machines went haywire, they don't want to believe that they've fallen for a bait and switch--the oldest scam in the book.  But it isn't hard to understand how this happens.

The come-on seems innocuous--open this interesting looking email or get a free something just for answering a couple of survey questions or download this free game or click on an interesting image.  There are hundreds of ways that scammers have of getting you to click.  And clicking is the key.

You may never know what you initially clicked on but what you have now is an official looking message warning you that you are infected with hundreds of viruses and Trojans and must download some software.  So you click the OK button or the Order Now button or any button at all and you are now directed to pay for the download.

If you don't pay you will keep getting the pop-up and will not be able to use your computer.  If you do pay for the download, you will have no more problems for maybe a week.  Then you will be asked to pay again with incessant pop-ups until you pay or bring in your machine.  We had one customer who paid three times before bringing in their machine.

Was there something you could have done to keep from getting infected? Possibly.  It is important to click on nothing the first time you get the warning that you are infected.  You must shut down your connection to the internet or shut down your machine immediately.  Even clicking on your browser to shut it down, could start the download process in which case shutting down the internet connection or your machine quickly is your only hope of avoiding the virus.

Try these steps:

  • Unplug your internet connection or shut off your wireless router if it is handy.  Or...
  • Press the on button (the button you use to turn on your computer) on your computer to shut it down.  If it is not shutting down quickly enough...
  • Press and hold in the on button on your computer until it goes off or unplug your computer.  This will do a hard shut down which is not good for your machine but it may do less damage than the virus you are about to download.  If you have a laptop you may have to unplug it and pop out the battery to get it to shut down.

Disconnecting and shutting down may not be enough if the program has successfully downloaded and installed.  These are small programs and they will download and install quickly.

If every time you reboot and reconnect to the internet, you get the warning messages, you are already infected and will have to bring your machine in to have it cleaned.