Thursday, January 8, 2009

virus scan scam struck me this morning

I was looking at some news on the web this morning and suddenly my browser window was gone and I had a window that warned me that my PC could become infected but... I could download software to scan my PC and all would be good.

Right...

I was about to be tricked into installing something that would not be good for me or my PC. I did some poking around about Antivirus 2009. Here is what I found:

It is a nasty virus/Trojan/bad thing, real easy to get, not easy to remove. You can find out a lot about it by searching for 'Antivirus 2009'. Be careful if you look at some of the sites that come up, you can end up on a site that infects your PC if you click without being careful. Here is a page from cnet.com that has a lot of info that you may find useful.
Help with Antivirus 2009 virus - CNET Spyware, viruses, & security Forums

Again, be careful, the info on the cnet site may be ok, and the fact that there are over 150 messages may... be a clue if you want to follow up on what others did.

I am using Linux/Ubuntu and I start out a lot safer than those of you that are using Windows/Mac computers. Here are some messages in response to a question about the virus on a PS3 running Linux.
[ubuntu] do i have the antivirus 2009 virus on my linux ps3 - Ubuntu Forums
Message #20 has something from someone's host support staff. Others claim that there are no real threats to linux PCs. However, it is better to be careful.

We tend to use Linux. It cuts way down on the dangers that are out there. I do not assume it eliminates them, just makes it harder for the bad guys to do something to you.

We tend to use Firefox to browse the web. I think that any of you that are using IE6 should stop doing anything and get Firefox NOW!

OK? Actually we use several browsers. I have used Apple's Safari and Google's Chrome and I do use Microsoft's IE 7 if I really need that browser. I plan on trying IE 8 when it has some mileage from others. Switching to Firefox or other browsers will not make you safe, I was on Linux using Firefox when I got attacked. It will make it a bit harder for the bad guys and that alone makes it worth switching to something safer.

and, let me say what I did. I knew that something was wrong when my browser window disappeared and the oh so innocent window popped up. I stopped and took a breath and looked at what was happening. My task bar showed Firefox running but I had that window that was not the usual browser window. The bar at the top told me
'The page at http://live-antiviruspc-scan.com says:' (do not click!!!)
And I did not remember going there. hmmm?

I tried to close the window by right clicking firefox in my task bar and selecting 'Close' and it would not go away. hmmm?

I found that if I moved the window my browser window was actually under it but very small. That was enough for me so I restarted my PC. That was probably overkill, and if I had already messed up and was infected, I could have made things worse.

Anyhow, I did some looking around when I was back up and decided to poke the bad page. I clicked on the link that got me into the mess the first time and sure enough it did so again. I wanted to find out what would happen if I clicked the Cancel button and was amazed when it started to spit out messages about files I know I did not have. I should have tried the close button on the top right, or killed it some other way.

It did not cause me more than some concern and took a little time. I was lucky.

I am glad I am using Linux.

My personal choice when using Linux is Chrome then Firefox.

A stop and look at what's going on as soon as something odd happens.

And I am only a bit safer. sigh

Gary

Mozilla | Firefox web browser & Thunderbird email client
Apple - Safari
Google Chrome - Download a new browser