Thursday, March 24, 2011

IMPORTANT: How to avoid catching a scareware infection

Scareware is the kind of malware/virus that pretends to be a security program.  It comes up and says you have an infection.  It says something that persuades you to click on a button; something like "click here to remove the infections."  Once you click on the button, your "hooked".  The scareware completely takes over your computer.  It disables your virus software.  It disables registry edits.  You can't bring up any function at all.  Your only option appears to be to click the botton.
 
DON'T CLICK THE BUTTON!  Not once, not ever!

Here's what you do:
  1. Manually turn off your internet.  Either pull your ethernet cable out and turn off your wifi using the hardware button or slider, or turn off your wifi.  If you have to, pull the power on your router.
  2. Turn off your machine.
  3. Turn your machine on.  With the internet disabled, you should be able to start your virus program and it will disable the scareware.  
In general, it is best to have a separate user account from the one you usually use.  In some cases, you can log onto that account and not encounter the scareware.  (The scareware installed its package under your id, not under the spare id.)  Run your virus program.

Also, in general, you should have Malwarebytes installed and keep it up to date by weekly downloading its signature file.   Run Malwarebytes instead of your virus software.  Let it remove the package.  Then run your virus software.

I can't emphasize enough that you should keep your virus software up-to-date.

As background, here is the problem.  The way this scareware installs itself is to download a package that does nothing but install a command to start the scareware the next time the computer is turned on.  That next time the scareware installs before the antivirus software can come up.  (If you have Microsoft Security Essentials installed, you might notice that the little icon at the bottom right of your screen is red for a little while after your session starts.  That is the vulnerable time.)  It uses the internet to complete the installation and disable your antivirus software. 

No comments:

Post a Comment

Printfriendly

Print Friendly and PDF