Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
Web

Fake Microsoft anti-spyware site stealing credit card info

  • Email a Friend
  • Print Page
Fake Microsoft anti-spyware site stealing credit card info
By Jim Carr
Oct 16, 2007 9:47 AM
Tags: Fake | Microsoft | ant-spyware | site | stealing | credit | card | info
The rogue site promotes a fake anti-spyware application called AntiSpyStorm, according to Avert Labs researcher Rahul Mohandas.

"Avert has blogged about rogue anti-spyware applications such as SystemDoctor, and we have probably classified several hundreds of them, if not thousands," Mohandas said in a blog post. "This threat appears to be a successor to the trojan FakeAlert-D."

The phony anti-spyware website offers an “online security scanner” that claims to search the visitor's system for viruses and spyware. After the fake examination, the site presents users with a fake list of trojans, prompting the user to download and install an ActiveX control to remove the threats.

The trojan then hijacks the infected PC's home page, shows fake alerts and exaggerated security threats and urges the user to install a trial version of AntiSpyStorm.

After installation, the phony product offers a free system scan, which reports a number of false positives. Users are prompted by AntiSpyStorm to download the full version, which attempts to trick the victim into entering credit card details to buy the non-existent product.

"The rogue anti-spyware is detected with the current DATS [McAfee virus-definition files] as 'Adware-AntiSpyStorm' and the fake ActiveX control is detected as 'FakeAlert-T,'" Mohandas said in his blog.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers