Friday, August 12, 2011

Bogus AntiVirus and Registry Apps

Computer Care: Beware of phony anti-virus apps; they're really malware



By Arthur Glazer
glazer.tech@gmail.com

POSTED: August 6, 2011 1:00 a.m.

Not all is what it seems when it comes to programs for your computer. There are so many rogue applications circulating the Internet now that one is sure to end up on your browser or in your inbox.

XP AntiVirus has been around for years and is still an active example of malware. Yes, you read that correctly. It is not an anti-virus program. It goes under various names including Windows AntiVirus, Vista or Win 7 AntiVirus and others.

In the past few months, I have removed more of these infectious programs from clients' computers than genuine viruses. Sure, there are still viruses out there, but malware is running a close race.

These so-called utilities will not clean your system, but will clean your wallet. They exist only to get your credit card number.

There are many types of bogus apps, some in the form of registry cleaners and system optimizers. They look like Windows utilities having the same color swatch or the shield that Microsoft uses for security issues. If you look closely though, there is no "About" button and no company name on the utility.

There's also the absence of an "X" on the upper right of the app to close it down. You can only scan or purchase. The "Close" or "Continue" buttons are greyed out so you can't click on them.

ThinkPoint is a similar rogue utility. It scares you into thinking your system is corrupt. After careful scrutiny, you'll see the only button you can click is "Safe StartUp." The "Normal StartUp" is greyed out.

They also want you to buy a nonexistent program.

These non-apps sneak into your system by intimidation. You are told of imminent system failure if a scan is not run or the app is not purchased. Don't fall for it.

You may be told there are 87 Windows registry errors that need to be fixed or removed immediately to continue. The fact is, once you see those warnings it's too late. You're already infected. It's not errors that need removing; it's that program.

It is not the job of Windows to report infections to you. If you have not initiated a scan, either manually or via a schedule, but scan results are reported to you, beware.

Often, the more you try to do something, the worse the situation gets. Each window you close yields another in an endless cycle. I've seen screens literally covered in pop-ups, severely limiting the ability to navigate. Safe Mode offers an alternative access to your system and may be the only option of repair for the lay person.

Beware of phony websites offering links to utilities and of redirects and hijacks. Make sure you end up where you ought to be, not at a similarly spelled site.

When you see links to downloads, they should come from reputable websites like cnet.com or download.com. They may also come from the author of the program. Scrutinize the source.

Avoid unknown websites; they may be full of infectious programs. Stick with name-brand sites you know or have been referred to by reputable sources.

If you get an email from an unknown sender with a link to a website or a program, don't click on it, no matter how enticing it may appear. You may also see links on Facebook, one of the largest sources of malware.

Should you believe your computer is infected, first do a full scan with whatever security utility you have. Then, if you don't have Malwarebytes on your system, download it and perform a full scan.

Use of a full-featured Internet security program is better than just a dedicated anti-virus utility. As stated, there are much more than viruses out there. You need to have the proper defenses installed.

The use of CCleaner and Spyware Doctor alone will not offer comprehensive protection for your system. Although both good programs, they need to be supplemented, just as an antivirus utility needs to be supplemented with a good spyware/malware utility.

Having the app installed is not good enough. Be sure the app itself, as well as its definitions, gets updated regularly.

Create a schedule to have it run. Let it scan your system while you're having dinner or sleeping (if the PC is left on).

Use applications that provide real-time protection. If you attempt to access a bogus site, those apps will advise you that it is not what it appears to be and block it.

Although many free apps like ones offered by AVG and Avast provide adequate protection, they lack all the bells and whistles that the paid versions offer.

It is important to note that only one anti-virus program should be installed on a system. You can, however, install multiple apps for protection against malware, including spyware, pop-ups, Trojans, key loggers, rootkits and the like.

Keep in mind that although it is good to be protected, too many programs running at startup that boot with Windows will tend to slow the system down.

That's another issue — and another column.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly on the Business page and on gainesvilletimes.com.

No comments:

Post a Comment

Got a Comment - or a quick question...