Archive for December, 2009

Rogue Security Programs – 5 in one week?

Saturday, December 12th, 2009
One of the more popular FAKE programs, Antimalware

One of the more popular FAKE programs, Antimalware

We had a new record setting week a couple weeks back.. 5 customers had computers with rogue software security programs. 2 of the 5 had to be completely reloaded with the operating system. The other 3 we were able to be cleaned out. I would like to share with you how you can know if you have these culprits on your system, and how to prevent them.

Sometimes these programs contain keyloggers, which will send back private information (credit cards etc) and can be source of identity theft. This is an issue not to be taken lightly.

Have you noticed a program on yours or somebody else computer that claims to be a security program, and that it has found tens or hundreds of errors, but you just need to buy the program license for it to “Fix” the errors? This is what you would call a Rogue Security program. And it is not necessarily in that of a virus category, as much as just malware/spyware. So alot of antivirus programs will not detect or block these programs.  But they are just as bad as a virus, sometimes worse.

Although good job security for companies like SOS Support is uneducated users that become infected with these hard to remove program, we believe its our ethical duty to educate you on protecting your computer, your data, and keeping your systems running smooth.

How do these rogue programs get there?

A program ALWAYS has to be ALLOWED on to your computer. Typically this happens when a user enters a website that is fraudulent. They got there one of many ways. A common way would be if they type a popular website URL in, but miss one character.  This is just one example.

Here you see a screen image of a website that is trying to install a program.

How it gets installed - via eerie websites

How it gets installed - via eery websites

Another example is, it could try to run through Internet Explorer ActiveX, where it will drop a bar below internet explorer asking what you want to do (Allow/Run?).

How to know if you have it?

If your computer is displaying a program that is “security” related and you dont remember eve seeing it before, or installing it knowing it was authentic, then you are probably infected. Also if your computer appears to be running slower then it once did (sometimes so slow you can barely work your way around), then you may be infected.

What to do if you are infected?

If you suspect you have a rogue security program, scan your computer for viruses. If your not up to date on anti-virus, and if your not using the program we recommend Sunbelt’s Vipre (refer to previous blog post), then you are not being protected and your chances of being infected are higher.  If your still having issues, contact us, and we could can help remove it.

The best prevention is knowledge of what is going on out there, and knowing when something that looks or appears legitimate is not. Always be aware of “Allowing” or “Run” – because all rogue software programs start with these two words.