Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Thursday, April 2, 2009

Don't Fall for it

We've been getting some cases of people's e-mail accounts being compromised and used for sending spam. This was generally because the user gave out his password.  Most commonly, people are tricked into it by an e-mail requesting the password.  Here is one example:

From: <Address removed>

Sent: Wednesday, April 01, 2009 7:03 PM

Subject: ATTN: EDU WEBMAIL SUBSCRIBER:

 

ATTN: EDU WEBMAIL SUBSCRIBER:

 

This mail is to inform all our {EDU WEBMAIL} users that we will be upgrading our site in a couple of days from now. So you as a Subscriber of our site you are required to send us your Email account details so as to enable us know if you are still making use of your mail box.

 

Further informed that we will be deleting all mail account that is not functioning so as to create more space for new user. so you are to send us your mail account details which are as follows:

 

*User name:

*Password:

 

Failure to do this will immediately render your email address deactivated from our database.

 

Your response should be send to the following e-mail address.

 

Your Admin Manager: <email address removed>

 

Yours In Service.

 

<name>

 

FROM THE EDU WEBMAIL SUPPORT TEAM

There are several things about this that should raise alarms.

  • First of all, no I&TS department will ever ask for your password. There is absolutely no need for it. In the case above, if we were upgrading our site, we'd would use your same user settings.  If, for some reason, we couldn't use your current username and password, we would create new accounts and let you know what the new information is. We would never have to ask for your password.
  • Note the phrase:  "we will be deleting all mail account that is not functioning." IT departments know the English language well enough to handle basic subject/verb agreement.
  • Though I hid it, the e-mail address for the Admin Manager was not a siena.edu address (it was from the .info domain, which is not all that reputable in any case).  Even if we for some reason needed this information (as I mentioned, we don't), we would ask you to send the e-mail to a siena.edu e-mail address.  This is a given.
  • At a college, it's pretty easy to know what student accounts are active and which aren't.  There is no reason at all to delete an account before you graduate. 
  • If space is needed, and we can't add memory, the solution would be to set quotas, not delete accounts.
  • "FROM THE EDU EMAIL SUPPORT TEAM."  Maybe it's just me, but I'm always suspicious about anything that comes from a "team."  Scammers always seem to use it.  While it can be legitimate, it's at least a warning flag.

There are many other signs of that an e-mail is fake; if you have an example, add a comment.  But the first rule is always the best: never give out personal information when replying to an e-mail.  If you have any doubts, contact the "sender" by another means -- by phone (finding the number in the phone book, not in the e-mail) or by visiting their web page (by typing the address into the address bar, not clicking on a link).

Here's a good overview of how to remain safe from phishing e-mails like this.

Thursday, March 19, 2009

Preventing Antivirus XP Infections

I've been talking alot about this and how aggressive and nasty it is.  Antivirus software is not effective, since it mutates constantly to sneak by — and once it's installed, it prevents any antivirus updates that might detect it.

There is one thing in your favor:  this malware is a trojan.  It cannot install itself on your computer; you need to install it yourself.  That's one reason why the warnings are so urgent — to make you take the one step required to get infected.

The problem is that when Antivirus XP 2009 pops up, it can be difficult to shut it down.  If you try to ignore the alert or close it, it will usually come back again and make it impossible for you to browse away from the infected page.

If this happens, the fix is simple:

  • Press Ctrl-Alt-Delete (i.e., all three keys at once)
  • A window will pop up.  Select "Task Manager."
  • The Task Manager will display.  Make sure the "Applications" tab is selected.
  • Look for Internet Explorer (or whatever web browser you're using).  They may be identified by the web page instead of the program name.  Identify it by the browser icon (the blue E for Internet Explorer, for instance).
  • Click on it.
  • Click on "End Task."
  • Look for other instances of your web browser, select, and click on "End Task" until they are all gone.
  • Close the Task Manager.

Your web browser is closed and the popup should be gone.

It's a good idea to use this method as soon as the Antivirus XP popup displays.

Were you infected?  It's certainly possible.  Luckily, you'll know pretty quickly if the malware was installed:  it will start nagging you to clean the computer, and you'll see virus warning you've never seen before.  If you don't notice anything different about your computer, you're probably OK.

Wednesday, March 18, 2009

How to Recognize a Fake Virus Alert Message

The various mutations of the Antivirus XP 2008/2009/360 viruses out there try to get you infected by giving out scary warnings about how your computer is infected with viruses.  A typical version looks like this:

 AV360 alert -- fake

Note these things:

  • It "detects" multiple infections.  It's unusual for a real alert to find more than one at a time.
  • The "online scanner" pops up in a second or so. It takes time to scan your computer -- ten minutes or more.  Anything that finds multiple viruses on your computer in only a couple of seconds is lying to you.
  • If you're using a web-based scanner, you must install software before it scans. If you haven't done this, it won't detect any viruses.  So if you haven't deliberately downloaded the software first, no scan will work.
  • A legitimate web-based scanner like Housecall only installs from a single site named for the scanner.  It does not show up if you don't deliberately go to it. The fake alert here will display when you're not going to a scanner website.

It's instructive to compare this alert with those of legitimate antivirus software.  Here are a few:

McAfee

Mcafee alert

Note this tells you that the file has been deleted or cleaned (click on the image and see the state).  It does not require any further action.

Symantec

(This may be an old image).

Symantec alert

This, too, doesn't require further action.  The virus is neutralized.

AVG

AVG Alert

AVG does give you options. "Heal" is usually the best. Note, though, that there's a single popup, and that it doesn't "strongly recommend" you remove them. 

Avast!

Avast alert

One nice thing about Avast! -- its warning says "There is no reason to panic."  This is quite the opposite of AV360, which wants you to panic. There are several options, and a suggestion for a recommended action.

Checking for yourself

If you're using different antivirus, or to get a better idea of what the warning looks like on your computer, download the EICAR Test File. Most antivirus software will detect as a virus (it is a harmless file used for testing antivirus).  When you download it, you should get a virus warning.  This will show that your antivirus is working, as well as giving yourself a chance to see a legitimate warning so you won't be fooled by the fakes.

Beware FileFixer Pro

The sleazes at Antivirus XP are at it again, and taking their nastiness to another level with FileFixer Pro. It is a very dangerous bit of spyware, because it keeps you from accessing your own data.

Like all the other version of Antivirus XP (2008, 2009, 360), File Fixer Pro appears as a popup while you're browsing the web that warns you in very heated terms that you files are corrupted and you'll need to install the program to fix it.

Don't do it!

Once the program is installed, it encrypts your files.  They're perfectly good, but you need to buy the software (for $60 or more) in order to read them.  If you do buy it, it will (probably) fix things -- but they now have your credit card and can run up charges on it.

While there are ways to remove File Fixer Pro, the files will remain encrypted.  At the moment, there is no way to fix this. (Added 3/25Tools are now available).

If a window pops up with this warning (or any other virus warning), close your web browser immediately.  The software won't install without your help.

Be very careful when browsing the web.  If you get a pop up warning you about a virus or problems with your computer, don't believe it.

Here is a discussion; information is still scarce, so be warned.

Tuesday, May 6, 2008

Ouch!

Ouch! by the Rutles.The SANS Institute is a organization of computer security professionals that provides training courses. But they also provide services to the general public, and their Ouch! newsletter is a great resource.

Ouch! covers current security threats -- spyware, viruses, phishing, bots, and other ways that hackers try to get personal data from your computer.  There are also security tips.

Ouch! comes out once a month. You can get an e-mail version by signing up at their web page.  It's a good way to keep up on potential threats.

Thursday, February 14, 2008

Snopes is Your Friend.

I mentioned Snopes earlier this week, and figured it needed some explanation.

Snopes has been around for at least ten years, and is a repository of urban legends run by Barbara and David Mikkelson. Every day (sometimes more often), the investigate reports of rumors and stories and try to determine their truthfulness. This isn't just an Internet search; they try to track down the people involved and interview them about the legend. The result is a definitive answer as to the truth of legends like "David Rice Atchinson was president of the US for one day"(he wasn't) or "Walt Disney's body was put into cryogenic storage" (of course not).

How does this fit in with computers? Well, there are many computing urban legends, about Computer Viruses, the Internet, and messages forwarded to your inbox. It's worthwhile checking out Snopes whenever you get any warning about computing issues that doesn't come from I&TS or directly from some other computer experts.

Thursday, August 2, 2007

No thanks for all the Phish

You're probably aware of this, but I thought I'd mention it: beware of phishing.

This is when scammers pretend to be a bank or other financial institution and send you an e-mail with a link. Usually, they give a seemingly urgent reason to go to the link and log in.

The entire goal is to get your login. From that point, they can go to the real site and log in as you and do whatever they want with your accounts. And, they aren't going to deposit money into them, that's for sure.

Banks don't send e-mails to their customers for anything important. If there were an issue, you'd get a letter or phone call. And don't be fooled because the website looks authentic; any web designer could do that in his sleep.

So never trust any e-mail from a "bank" (or from "Paypal" or "eBay") that urges you to log in (especially when there are spelling and grammar errors). If you have any questions, call the bank, or type their web page directly into your browser.