BY ERIK LARKIN

MICHAEL VANA WAS skeptical when he saw the pop-up from “Antivirus 2009” on his screen. e former Northwest Airlines avionics technician, who lives in Schaumburg, Illinois, guessed that the dire warning of a system infection was fake, but when he clicked the X to close the window, it expandedto =ll his screen. To get rid of it, he had to shut down his PC. Sound familiar? Dirty tricks like these, designed to get you to install and buy fake antivirus products, are more common than ever. But while you might recognize such warnings as bogus, you might not know that the fake warning could be a red alert about an underlying bot malware infection. Knowing the di`erence is key. “It’s not something you even blink at anymore,” says Christopher Boyd, senior director of malware research for communications security company Facebme Communications, of requests for help in dealing with phony warning pop-ups. De increased incidence of such pop-ups is due to more crooks going ader easy money from shady aeliate rograms, which pay a huge cut of the pro=ts—up to 90 percent—for every person who istakenly
hands over money for a fake program, regardless of what in - duced them to pay. Oden, the nducement comes from a malicious Web site that employs JavaScript tricks to unleash a horde of op-ups, or even resize the victim’s browser window, to create something that looks like a real antivirus scan. You might reach such a site by using a bad search link, like the one Boyd clicked for a free online Batman game. He got redirected to a site that took over his browser to display a fake antivirus scan, which then found (=ctitious) critical infections that he could supposedly =x by buying the rogue antivirus app. If a site merely hijacks your browser, you don’t have to worry too much: De pop-ups or fake scanner windows don’t cause lasting damage, Boyd says. You might be prevented from closing the window, as Vana was, but you can usually bring up the Windows Task Manager with and close your browser thatway. Sometimes just pressing will shut it down. “To do this, [the fake site] uses real code, and oesn’t generally exploit a hole,” Boyd says. As long as you don’t panic and install the pushed program, no real harm occurs.

0 komentar