The Register® — Biting the hand that feeds IT

Feeds

Scareware tries to trick marks into dropping defences

Strip for me, baby

Customer Success Testimonial: Recovery is Everything

Virus authors have developed a strain of malware that attempts to con users into uninstalling legitimate security packages.

A rogue package called AnVi Antivirus generates a cheeky pop-up message suggesting that legitimate apps are “uncertified" and ought to be removed. Failure to take action would result in drastically degraded computer performance, marks are disingenuously warned.

Many malware packages, including the Conficker worm, are designed to silently disable anti-virus software and security updates on infected machines. The AnVi Antivirus rogue differs because it uses social engineering techniques in an attempt to trick users into uninstalling security packages.

The rogue will also attempt to remove legitimate packages from the likes of Microsoft, AVG, Zone Labs and Norton even if users fail to comply with the bogus request to uninstall pukka security software. Such an approach, of course, ought to be blocked if the security packages are doing their job.

But on machines with outdated security definition files the attack may work.

If successful, AnVi Antivirus will download fake anti-virus software that warns of multiple imaginary security threats in a bid to trick victims into purchasing worse-than-useless crapware.

A write-up of the threat - complete with screenshots - can be found in a blog post by Symantec here. ®

Bootnote

As with many plausible cons the approach followed by AnVi Antivirus harbors a grain of truth. Legitimate anti-virus packages, by their nature, rely on low-level access to machines on which they run and do not play well together with other anti-virus packages on the same PC, as explained here.

Ensure Ease of Recovery with Asigra’s Agentless Software

Ouch

Some things are more trouble than malware. I'd rather stick with Windows, thanks.

16
3

You mean the Amigh virus:

Thou hast just received the Amish Virus.

As we haveth no technology nor programming experience, this virus worketh on the honour system. Please delete all the files from thy hard drive and manually forward this virus to all on thy mailing list.

We thank thee for thy cooperation.

4
0

Irish virus

Is it me or is this very close in technique to the Irish virus that was doing the rounds about a decade ago?

http://www.jokefile.co.uk/computer_jokes/pic31661.jpg

4
0

More from The Register

 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats
Critical Java SE update due Tuesday fixes 40 flaws
And yes, most are remotely exploitable
NSA accused of new crimes ... against slideware
They may take our information but they cannot take our REFINED AESTHETICS