Get more | Tech Alerts

Anti-malware-scanner.com: Fake Malware Scanner Site Brings Popup to Mac and Windows

While antimalware.com’s malware Antivisus2009, etc probably cannot affect Macs, it is best to avoid any risk by using the COMMAND-OPTION-ESC key combination to effect a FORCE QUIT of Safari when a malware scanner popup appears. Don’t click on the popup, don’t click on the OK button, and don’t click on the CANCEL button. More Windows information below.

antimalwarescannercom2
What does a malware popup look like? Screen shots show the popup and the FORCE QUIT APPLICATION window that allows users to quit Safari without engaging the antimalwarescanner website. This antimalware.com popup appeared on a Mac on February 5, 2009. If you use Windows, press CTRL + ALT + DELETE to open your Task Manager, and click “End Task.”

Norton Safe Web Alert for anti-malware-scanner.com & antimalwarescanner.com
anti-malware-scanner.com
antimalwarescanner.com

The websites mentioned above are possibly from Luxembourg and distribute fake scanner malware. The websites are associated with distribution of MS Antivirus, also known as XP Antivirus; Vitae Antivirus; Windows Antivirus; Win Antivirus; Antivirus Pro; Antivirus Pro 2009; Antivirus 2007, 2008, 2009, 2010, and 360; System Antivirus; Vista Antivirus; AntiSpywareMaster; and XP AntiSpyware 2009, is a scareware rogue anti-virus which claims to remove bogus virus infections found on a computer running Microsoft Windows if a user purchases the full version of the software. More on possible criminal connections of American citizens with these websites, below.

Windows Users
MS Antivirus is known to infect users using the Microsoft Windows operating system, and is browser independent. MS Antivirus is made to look professional and functional to fool a computer user into thinking that it is a real anti-virus system in order to convince the user to “purchase” it. In a typical installation of Antivirus 2009 or MS Antivirus, the malware runs a scan on the computer and gives a false spyware report claiming that the computer is infected with spyware. Once the scan is completed, a warning message appears that lists the spyware ‘found’ and the user has to either click on a link or a button to remove it. Regardless of which button is clicked — “Next” or “Cancel” — a download box will still pop up. This deceptive tactic is an attempt to scare the Internet user into clicking on the link or button to purchase MS Antivirus, Antivirus 2009 or malware with other names. If the user decides not to purchase the program, then they will constantly receive pop-ups stating that the program has found infections and that they should register the antimalware in order to fix infection. This type of behavior can cause a computer to operate slower than normal. The infection affects the Windows registry.

Most variants of this malware will not be overtly harmful, as they usually will not steal a user’s information (as spyware) nor critically harm a system (bring a complete shutdown or erase hard drive data). However, the malware will act to inconvenience the user by frequently displaying popups that prompt the user to pay to register the software in order to remove non-existant viruses. Some variants are more harmful; they display popups whenever the user tries to start an application or even tries to navigate their hard drive, especially after they restart their computer. It does this by modifying the Windows registry. It can also disable real antivirus programs to protect itself from removal. Whichever variant infects a computer, MS Antivirus always uses system resources when running, potentially making an infected computer run slower than before infection.

The malware can also block access to known spyware removal sites and in some instances, searching for “antivirus 2009″ (or similar search terms) on a search engine will result in a blank page or an error page. Some variants will also redirect the user from the actual Google search page to a false Google search page that states that the user has a virus and should get Antivirus 2009 with a hotlink to the malware’s distribution/registration page.

MS Antivirus (Antivirus 2009) is constantly updated and re-released to prevent detection by common anti-virus scanners.

AntiVirus2009 can also disable a user’s antimalware programs and prevent the user from opening or re-enabling them. Antimalware applications disabled by AntiVirus2009 include McAfee, Spybot – Search & Destroy, AVG and Superantispyware.

How Criminals Gain by Annoying Users and the Criminal Charges
Innovative Marketing, Inc. is the company being investigated by the FTC with allegations that Innovative Marketing, Inc. is behind the malware deception. Criminals involved in the malware scheme gain income by charging $39.95 or more to people duped into believing registration for full versions of software would rid their computers of the malware that (1) didn’t exist and then (2) DID exist after a click on a popup caused download of malware that slowed down the user’s computer and caused even more annoying popups to appear.

MyGeek (an Internet advertising agency) and advertising partners were victims as the ads displayed by distributors of the malware contained autodownload commands that placed malware on user’s computers without their consent.

Innovative Marketing, Inc. is also accused of creating sham Internet advertising agencies (Burn Ads, Preved Marketing, AdTraff, NetMediaGroup, and Uniqads) that offered to purchase ads on legitimate company websites, such as CareerBuilder.com, FrontGate, Travelocity.com, Priceline.com and OxFam International (an anti-poverty charity). Innovative Marketing, Inc. is accused of using a technique of blocking their suspicious ads from IP addresses where legitimate companies, such as Priceline, would review ads from the advertising agency. Executives of innocent companies would approve different ads — having never seen the suspicious malware ads.

Don’t Blame Your Favorite Website!
A similar method of deceptive Internet address techniques also apparently resulted in Innovative Marketing, Inc. ads directing visitors of websites, such as Major League Baseball (mlb.com), the National Hockey League (nhl.com), The Economist Magazine (economist.com), the National Associaton of Realtors (realtor.com), Zillow.com, E-Harmony Dating Site (E-Harmony.com) and more to cause bogus Internet scans, alerts and autodownloads. The redirection and popups could occur without users even clicking on any ad banners. The malware popup can appear while a page is idle or while a user switches to another page or website.

Affiliate networks are also duped when the malware causes false clicks that earn affiliates money for each click.

According to an FTC complaint, two companies are charged in the case – Innovative Marketing, Inc. and ByteHosting Internet Services, LLC – they operate using a variety of aliases and maintain offices in various countries. Innovative Marketing is a company incorporated in Belize that maintains offices in Kiev, Ukraine, Argentina and India. ByteHosting Internet Services is based in Cincinnati, Ohio. Individuals named in the charges are James Reno (ByteHosting — website temporarily unavailable as of Feb. 5, 2009), Sam Jain (CEO Innovative Marketing), Daniel Sundin (Innovative Marketing), Marc D’Souza (Innovative Marketing,), Maurice D’Souza (related to Marc), and Kristy Ross (Innovative Marketing).

On December 2, 2008 the U.S. District Court for the District of Maryland issued temporary restraining against Innovative Marketing, Inc. (FTC v. Innovative Marketing, Inc. case info) and ByteHosting Internet Services, LLC after receiving a request from the Federal Trade Commission (FTC). According to the FTC, the combined malware of WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus has fooled over one million people into purchasing the software marketed as security products. The court also froze the assets of the companies in an effort to provide some monetary reimbursement to affected victims. The FTC established claims that the companies established an elaborate ruse that duped Internet advertising networks and popular Web sites into carrying their advertisements.

What to Do If You See A Malware Popup
If you’re faced with any of the warning signs of a scareware scam or suspect a problem, shut down your browser. Don’t click “No” or “Cancel,” or even the “x” at the top right corner of the screen (Windows) or the red circle at the top left (Mac). Some scareware is designed so that any of those buttons can activate the program. If you use Windows, press Ctrl + Alt + Delete to open your Task Manager, and click “End Task.” If you use a Mac, press Command + Option + Esc to “Force Quit.”

If you get an offer, check out the program by entering the name in a search engine. The results can help you determine if the program is on the up-and-up. But if you are already infected, you may be directed to sites that cause more harm and you may not even see the sites that can help you.

Good Security Practices
Malware can be a minor annoyance, but usually leads to a major slow down of computers. Malware can also come in the form of keyloggers and “bots” or even programs that can be set by organized criminal gangs to coordinate multiple attacks of computers of major companies or the government. For example every infected computer with the right “bot” can be signaled to attack a major server of importance to the government or the economy. These DoS or Denial of Service attacks can cause a computer resource to become unavailable to its intended users. Target sites include credit card payment gateways, banks, and the Pentagon. They have even been used in acts of revenge to attack host companies that contain services that fight e-mail spam.

Check that your security software is active and current: at a minimum, your computer should have anti-virus and anti-spyware software, and a firewall. You can buy stand-alone programs for each element — or a security suite that includes these programs — from a variety of sources, including commercial vendors and your Internet Service Provider. The security software that was installed on your computer when you bought it generally works for just a short time — unless you pay a subscription fee to keep it in effect. Visit http://security.getnetwise.org/tools/search for a list of security tools from legitimate security vendors selected by GetNetWise, a project of the Internet Education Foundation.

Make it a practice not to click on any links within pop-ups.

Report possible fraud online at ftc.gov or by phone at 1-877-FTC-HELP. Details about the purchase — including what website you were visiting when you were redirected — are helpful to investigators.

Visit OnGuardOnline.gov to learn more about protecting your computer from bugs, viruses and scammers.

The FTC enters consumer complaints into the Consumer Sentinel Network, a secure online database and investigative tool used by hundreds of civil and criminal law enforcement agencies in the U.S. and abroad.


ARLINGTON HEIGHTS BREAKING NEWS --The Cardinal -- Arlingtoncardinal.com is a breaking news blog with Arlington Heights & Chicagoland emphasis. For in depth coverage, please check the following links for network television, cable news networks and Chicago local media coverage ...

Daily Herald | Daily Herald -- Arlington Heights | YouTube.com/DailyHeraldClips
Today's headline videos: FOXNews Video | YouTube.com/FoxNews | Associated Press
Chicago Area Newspapers
CNN Arlington Heights  FOXNEWS  BREITBART.COM  cbs2chicago  NBC 5 Chicago  abc7chicago   WGNTV      WGNRADIO720  NEWSRADIO 78  CHICAGO BREAKING NEW  Daily Herald Arlington Heights  Chicago Tribune   Seed Newsvine
 
Video LOGO youtube Twitter Arlingtoncards facebook battery status Cardinal Calendar Search Batteries Plus RSS Help ...
All Headlines
crimeblog | fireblog
« EARLIER | SEARCH ARTICLES BY DATE -- Arlingtoncardinal.com/searchdate | LATER »
^^ Titles listed left published before current article. Titles listed right published after current article. ^^
Article titles above span across all categories of Arlingtoncardinal.com.

Comments for Arlingtoncardinal.com

6 Comments For This Post

  1. psyche Says:

    But what if you clicked on the red circle (mac) to get rid of it and activated it? I couldn’t get Safari to quit after that, until I clicked “OK” to get out of it. I couldn’t restart my computer or anything without finally clicking “OK” once I tried to get rid of it the other way. Ugh.

    So what do I do? What can happen?

  2. admin Says:

    Most likely it is not activated because it is software that is made to work on a Windows PC, so on the Mac it would just sit inactive on your Mac’s hard drive. For peace of mind, you can download MacScan 2.6 from Apple.com (official site) and follow instructions for security check. http://www.apple.com/downloads/macosx/networking_security/macscan.html

    The software will find a lot of cookies for sure. But it should also alert you and help you quarantine anything more harmful.

  3. admin Says:

    PS … you can then periodically check your Mac with MacScan. In the preferences you can set MacScan to clean your preferred browser(s).

  4. Jaurita Says:

    What if you are a window’s user and the browser was not shut down correctly (OK, cancel or the x was clicked instead). Now the pop up comes up dozens of a times a day. McAfee reports that the virus is on the computer, but states that it cannot clean it. How do we deal with that situation?

  5. admin Says:

    Since you have a McAfee product, contact McAfee …
    http://www.mcafee.com/us/medium/products/system_security/clients/anti_spyware.html
    Look in the upper right corner for chat or toll free number.

    or check McAfee customer service page …
    http://service.mcafee.com/Default.aspx

  6. CG Says:

    What if you’re a window’s user and the pop-up wasn’t shut down correctly? When I run the Norton 360 scan, it shows that there are no threats. Should I trust that?

Know More About Topic? Have an Opinion? Comment Here ...

Please remember that any individual can falsely claim to be a doctor, lawyer, or financial advisor, etc., and leave misleading statements. Use your discretion in validating statements. The Cardinal is not responsible for content in the comments section.

Comments are not always posted immediately because a moderator checks
each comment to prevent posts of hateful language, obscene language,
commercial or irrelevant messages (spam), and outrageous attacks.
Thank you for your comments. Most comments are approved within 12 hours.
Some comments are approved within minutes.

SUBMIT CRIME TIPS ...
Anyone having information about serious crime in Arlington Heights should register on CitizenObserver.com and look for the anonymous TIP411 feature, or call Arlington Heights Crime Stoppers at 847-590-STOP (847-590-7867). Callers are guaranteed anonymity and may qualify for a cash reward of up to $1,000. Not a resident of Arlington Heights? Check CitizenObserver.com for availability for your community.

REFERENCE TOOLS & CALCULATORS ...
Fitness Calculators -- FitnessMath.com | Unit Convertor from FitnessMath.com | Calculator | Stopwatch
World Health, Epidemic, Pandemic, & Flu Map -- WorldwideHealthMap.com
Military & Terror Conflict Regions -- GLOBALCONFLICTMAP.COM

STREETS OF ARLINGTON ...
Arlington Heights Street Map | Distance & Size Calculator | Chicago Sports & Entertainment Locations
United States Map | World Map

Use the drop down menu menus directly under the Front Page images at the bottom of all articles. Some of the links include the following:
Chicago Tribune | Chicago Sun-Times | Daily Herald | Daily Chronicle (Springfield, IL) | Kane County Chronicle | Northwest Herald (McHenry County) | Journal & Register (Springfield, IL) | USA TODAY | RedEye

CNN | FOXNEWS | cbs2chicago | nbc5 | abc7chicago | wgntv | CLTV | myfoxchicago | PIONEERLOCAL
Arlington Heights Post | WGN 720 | newsradio 78 | chicagobreakingnews -- Search Results Arlington Heights

Loading...


 
Fitness Tips Health News

Exercise Reports
EXERCISE-REPORTS.COM (main)
exercisereports.com (journal)

Exercise, Sports Medicine
Nutrition News & Journal
Nutrition Data & Analysis
FITNESSMATH.COM calculator
Anatomy/Physiology reference

Fitness is a luxury in prosperous times. Fitness is a necessity in tough times. Strength, stamina, injury prevention and disease prevention are priorities, especially in tough times when lowered health care costs and productivity are important.
Don't Let the News Wear You Down!
Affirmations and Adapatation are key to success!

1. Exercise everyday. 2. Lift weights 3-5 days per week. 3. Get cardiovascular exercise 3-5 days per week. 4. Walk every day. 5. Learn posture and anatomy and optimal body mechanics for safety and injury prevention. 6. Drink plenty of water. 7. Learn nutrition and healthy eating. 8. Learn your optimal consumption of macronutrients (carbohydrates, protein and fat) and consume accordingly. 9. Get enough rest and sleep. 10. Be intelligent: Learn and adapt to the changing world.

Sports medicine, medical news, fitness news & more ...
Exercisereports.com for Health & Fitness News ...


 

COOLFITNESSGIFTS.COM FITNESS/SPORTS
Baseball products -- baseballs, pitching machines, batting batting gloves, baseball mitts, baseball helmets, baseball bats ...
Basketball products -- backboards, basketballs, basketball nets, chain nets, basketball hoop lights ...
SPRI Products -- exercise tubing, SPRI Xertube, SPRI Travel Kits, SPRI Wall Charts, SPRI Xerball Medicine Balls ...
BOSU -- BOSU, the blue half-ball that's great for balance ...
Physioballs and Swiss Balls ...
Sports Bras -- Calvin Klein bras, DKNY bras, Maidenform bras, Under Armour sports bras...
Under Armour -- UA Heat Gear, UA Cold Gear, Under Armour Shirts, Under Armour Shorts
Resistance Weights -- Dumbbells, Hex Dumbbells, Vinyl Dumbbells, Power Blocks, PlateMate ...

Sports medicine, medical news, fitness news & more ...
Exercisereports.com Health & Fitness News ...

 
Cool Fitness Gifts
 
 

Streets of Arlington Heights
STREETSOFARLINGTON.COM
MAPS FOR ARLINGTON HEIGHTS ...


POPULAR LINKS

AHS Film Documentary ...
The Arlington High School Film Documentary "The Lady in Red"


Arlington Heights American Legion Post 208 Baseball at Recreation Park
Lloyd W. Meyer Field -- Arlingtoncards.com/post208


Arlington Heights Restaurants

Arlington Heights Fast Food
Arlington Heights Pizza
Arlington Heights Sushi
Arlington Heights Bars

Arlington Heights Weather

Arlington Heights Health & Fitness
Arlington Heights Hair Salons
Arlington Heights Commute
Arlington Heights Real Estate
Arlington Heights Hotels
Arlington Heights Gardening

Arlingtoncards.com Site Map


Buffalo Grove High School
Football Schedule


Hersey High School Football Schedule


Prospect High School Basketball Schedule


St. Viator High School Football Schedule


FESTIVAL 2010
Arlington Heights Frontier Days

Chicago-Shops.com: Map of Shopping Malls Near Chicago | Chicago Area Airports and Airport Maps

Arlington Heights Blog
© Copyright 2006-2010 Apriori, Inc.
Arlingtoncards.com, THE CARDINAL, Arlingtoncardinal.net, DIGITAL LIFESTYLE, and digital-lifestyle.com are copyright of Apriori, Inc. AA-ER.COM. Life, Liberty, and the pursuit of happiness

  Apple iTunes   Apple iTunes
spacer
 

Cool Fitness Gifts

Great Fitness Gifts on CoolFitnessGifts.com
AIDS/HIV Awareness/Condoms

Sports Bras
| SPRI Products
SPRI Tubing
| Anatomy Models
Baseball Products | Basketball ProductsBOSU
Dumbbells | iPods | Total Gym


CHICAGOFANFARE.COM
Chicago Cubs Caps | Chicago Cubs Merchandise


iTunes HITS FOR LAST MONTH

iTunes Store: Top Songs in March 2009