Feeds

Washington and Microsoft declare war on scareware

One down, but how many more to go?

Next gen security for virtualised datacentres

Washington state's top law enforcement official has filed suit against a man accused of bombarding end users with misleading messages designed to trick them into buying software to fix PC problems that don't exist.

The complaint, filed in Washington state court by Attorney General Rob McKenna's office, names James Reed McCreary IV of The Woodlands, Texas, and two of his companies, Branch Software and Alpha Red. They stand accused of pushing a software package called Registry Cleaner XP by sending end users messages falsely claiming their PCs have corrupted or damaged registry settings that must be repaired immediately. The software sells for $40.

In many cases, the warnings are delivered using Windows Messenger Service, a network administration utility for delivering system-wide messages to end users. The popup windows claim to be generated by the "Local System" and warn of a "critical error" related to the end user's registry. The messages were directed to a wide swath of internet protocol addresses, and in many cases were sent over and over, causing hundreds of windows to open that the user has to close individually.

The prevalence of so-called scareware has reached epidemic proportions. Programs frequently mimic real security features within the Windows operating system to fool people into believing their PC has been infected with malware. In many cases, it's just about impossible to remove the software once it's been installed.

"Through alarmist language seemingly delivered by a trusted source, defendants misrepresent the extent to which installing the software is necessary for repair of the computer for proper operation," the complaint argues. The error messages, which appear on machines free of any problems, "induces the consumers to purchase defendants' product, which must be used in order to 'repair' the 'errors.'"

Attempts to reach McCreary, Branch Software and Alpha Red were unsuccessful. A number listed as belonging to McCreary had been disconnected. No one answered a phone listed in this whois listing as belonging to Branch Software.

Microsoft referred the case to McKenna's office and has been helpful in assisting the AG's consumer protection high-tech unit to enforce laws against scareware mongers. Over the past three years, Microsoft has brought 17 lawsuits under Washington's Computer Spyware Act and the state's attorney general has filed seven.

Yes, the enforcement actions are a step in the right direction, but we question the efficacy of this finger-in-the-dike approach. Despite filing a raft of suits they find themselves back in court again. And at time of writing, registrycleanerxp.com continued to offer free registry scans. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?