Ads

New Malware Disguised as McAfee VirusScan Trial

8:10 PM - July 28, 2010 - By Kevin Parrish - Source : Tom's Guide US

Scarware is heading to your Inbox disguised as McAfee VirusScan Plus.

Wednesday security firm Sophos warned Internet surfers of fake anti-virus software that's posing as a free 30-day trial of McAfee VirusScan Plus.

Sophos senior technology consultant Graham Cluley said that the company's spam traps intercepted a wave of malicious emails overnight that claim to offer the supposed McAfee trial. Instead, it delivers malicious cargo known as Mal/FakeAV-El.

"Download a FREE 30-day Trial of MCAfee VirusScan Plus and Be Automaticaly Entered to Win.," reads the email. "Installation file attached."

The accompanying file is setup.zip.

McAfee also acknowledged the bogus anti-virus spyware, saying that it's a new variant of the Bredolab Trojan. The firm also pointed out the email's spelling errors (no, it wasn't me this time) and that McAfee never distributes setup files as an email attachment.

"Fake anti-virus software (also known as scareware or rogue anti-virus) continues to be a big problem," Sophos' Cluley added. "Malicious hackers create programs that pretend to be legitimate anti-virus products, but are actually designed to frighten you into believing you have security problems with your computer (in the hope that you'll pay up for a cure)."

Naturally the best way to avoid problems stemming from fake anti-virus software is to avoid these types of emails--and have a real product installed.

Comments

Read the comments on the forums
JonathanDeane 07/29/2010 2:30 AM
Hide
-8+

What do you mean "Disguised" lol just kidding.... But nothing surprises me these days what the malware does. Next up they will hack dns and hack MS's auto update feature and push out hacked signed "updates" from fake microsoft update servers.

mp562 07/29/2010 2:31 AM
Hide
-20+

I'm sooooo sick of these people. I wish someone would just take 'em out and hang 'em.

jhansonxi 07/29/2010 2:40 AM
Hide
-20+

I wonder if it is less of a system hog than the real one.

jhansonxi 07/29/2010 2:41 AM
Hide
-17+

mp562 :
I'm sooooo sick of these people. I wish someone would just take 'em out and hang 'em.

Who? The people who created it or the fools who fall for these scams?

pojih 07/29/2010 2:42 AM
Hide
-14+

Why would anyone download that?

Some people should really take a class on how to not do stupid things like this.

...sigh, you all know one of them, you fix their computer for them, put an AV on it - and they disable it - and call again.

jtt283 07/29/2010 2:45 AM
Hide
-1+

Stop playing games. If a purveyor of malware is convicted (an individual is innocent until proven guilty), stick his head in a bucket and pull the trigger. GAME OVER.

JonathanDeane 07/29/2010 2:49 AM
Hide
-5+

pojih :
Why would anyone download that?Some people should really take a class on how to not do stupid things like this....sigh, you all know one of them, you fix their computer for them, put an AV on it - and they disable it - and call again.



Or my favorite trick, you spend hours working on a machine to repair it and "save my files!!!!" only to have them use system restore to undo your system tweaks and get reinfected with the updated versions of the crap you just spent forever removing.... It took me a few times but I figured out when your cleaning up some ones machine don't be nice and leave system restore alone "Nuke it from orbit".

liquidchild 07/29/2010 2:49 AM
Hide
-0+

This is not new.....my moms computer BSDed 4 months ago. I had to reinstall EVERYTHING and lost a lot of family pics. I suspected the free trial but could not prove it as im not a PC wiz. Great job in finding the bug who ever did.

snotling 07/29/2010 3:09 AM
Hide
-1+

mp562 :
I'm sooooo sick of these people. I wish someone would just take 'em out and hang 'em.


you mean the people at Mcafee? LOL

captaincharisma 07/29/2010 3:35 AM
Hide
-3+

snotling :
you mean the people at Mcafee? LOL



nah that too harsh for the msafee people. now the people at symantec who keep making Norton well that's another story :)

warmon6 07/29/2010 3:45 AM
Hide
-1+

Ug. I get tried of seeing thoses advertising bots, spamming the forums and article about a product or website. Tom's Cant you just add a security captcha's for the login process? Im more than sure that most of them are bots and not real people.
___________________________________________________________

Anyways,

pojih :
Why would anyone download that?Some people should really take a class on how to not do stupid things like this....sigh, you all know one of them, you fix their computer for them, put an AV on it - and they disable it - and call again.



That sounds familiar..... Have you been watching me? :lol:

I just had to do close to that only a few weeks ago. Although i never was able to fix it. Due to all the tools i would of needed to "fix the issue" was all packed away on a trailer that was already on the road to my new house [:isamuelson:8] ...... Out of all the time that a friends computer get's a virus when im still around, It had to be when i had really nothing to work with. Yeah had a 16GB flash drive with tools on it (Stuff from linux pendrive tools like avg anti-virus, few linux OS's, ect) that would of done the job but to bad the computer was old enough to not be able to run off a flash drive very well.

Sigh, Anyway yeah my friend computer had anti-virus but scene It had norton on it (which needs payed yearly), my friend didn't keep up with the payments and well, you get the idea.

I agree though, everytime there a problem (via virus situation) it always seams to happen to the same people for the same reason. Then the phone call call comes, you fix, then deja vu.

captaincharisma 07/29/2010 3:46 AM
Hide
-2+

JonathanDeane :
Or my favorite trick, you spend hours working on a machine to repair it and "save my files!!!!" only to have them use system restore to undo your system tweaks and get reinfected with the updated versions of the crap you just spent forever removing.... It took me a few times but I figured out when your cleaning up some ones machine don't be nice and leave system restore alone "Nuke it from orbit".



this goes to show that some people just should not own computers

im_thelumberjack 07/29/2010 4:05 AM
Hide
-4+

somehow I think the virus does less harm then the actual McAfee product.

matt87_50 07/29/2010 4:06 AM
Hide
-2+

lol, I always though legit McAfee caused your system more grief than any virus it could protect you from. so telling it apart from this malware imposter may be difficult!

I suppose if it all of a sudden it isn't slowing your computer to a crawl and making everything painful, it must be the virus!

danimal_the_animal 07/29/2010 4:18 AM
Hide
-0+

This is three years old!!!!!!!!!!!!!!!!!!!!

and you are barely writing about it now?

speedemon 07/29/2010 5:02 AM
Hide
-0+

liquidchild :
This is not new.....my moms computer BSDed 4 months ago. I had to reinstall EVERYTHING and lost a lot of family pics. I suspected the free trial but could not prove it as im not a PC wiz. Great job in finding the bug who ever did.



Couldnt have been a hardware error... naw it must be that virus

fletchoid 07/29/2010 5:26 AM
Hide
-1+

My favorite is when you install AVG Free, set up the schedules for updates, and scans. Write a little blurb on how they should leave their computer on overnight at least once a week to let the software scan and protect their computer, and then a year later, they mysteriously get a virus, and when you look at the antivirus, the last update and scan was the one you did a year ago.
I charge extra for those people.

rohitbaran 07/29/2010 5:37 AM
Hide
-0+

Quote :Naturally the best way to avoid problems stemming from fake anti-virus software is to avoid these types of emails--and have a real product installed.

The last two lines clearly show who has major incentive behind designing these malware. The security companies themselves. :/

chickenhoagie 07/29/2010 6:28 AM
Hide
-0+

perfectly fine with me. more money comin my way. keep exposin the idiots malware producers! i'm makin bank off this.

1337_b0i 07/29/2010 7:01 AM
Hide
-2+

Well isn't McAfee malware anyway? I mean it fills up RAM and eats up your CPU.

eddieroolz 07/29/2010 7:02 AM
Hide
-0+

Just removed a pretend-anti-malware software from the computer of my friend's family. These things are really good at scaring people.

hardcore_gamer 07/29/2010 9:15 AM
Hide
-0+

its nothing..dell shipped motherboards with malware

Maxor127 07/29/2010 3:38 PM
Hide
-2+

I was infected by a nasty virus a couple weeks ago. I visited gamecopyworld. Just browsed. Didn't download anything. Next thing I know, I'm getting UAC alerts for a program to install. I kept denying it access but it kept popping up and trapping my computer in the gray UAC void. I finally managed to get to the task manager and end a suspicious process and the UAC alerts finally stopped. But somehow a virus posing as an anti-malware scanner got installed anyways through my anti-virus guard and the UAC. Took me a whole day to finally clean it off my computer. I was close to just clean installing everything until I finally found the right combination of anti-virus tools to get rid of all traces of it.

regulas 07/29/2010 3:43 PM
Hide
--3+

This is getting bad and there seems no end in site. This does give a person a reason to give second thought to Apples approach to a closed system even though they had one program that got approved and stole info from users.
This just in about the new Droid:
Android wallpaper app exploit stole info from millions of users.
http://www.mobileburn.com/news.jsp?Id=10167

ihs97 07/29/2010 3:44 PM
Hide
-1+

Capital punishment is too good for these hackers. I'd hand them over to Marcellus Wallace to get medieval on their asses.

I'm so tired of fixing family computers due to malware that I have actually started recommending they get a Mac Mini. Sad I know, but it saves me the time having to clean out their systems.

regulas 07/29/2010 3:45 PM
Hide
--2+

hardcore_gamer :
its nothing..dell shipped motherboards with malware


But where did the motherboards come from, $100 bucks says they were made in China

LORD_ORION 07/29/2010 3:52 PM
Hide
-0+

There are so many things that can get past UAC and anti-virus that I simply reimage when my system starts acting up. Something is wrong if I make a typo in a URL and end up in a bad place, and suddenly I start getting scare ware browser windows even though I am not surfing.

Can't trust your browser no matter how good you are, it is as simple as that.

teaser 07/29/2010 3:54 PM
Hide
-1+

Maxor127 :
I was infected by a nasty virus a couple weeks ago. I visited gamecopyworld. Just browsed. Didn't download anything. Next thing I know, I'm getting UAC alerts for a program to install. I kept denying it access but it kept popping up and trapping my computer in the gray UAC void. I finally managed to get to the task manager and end a suspicious process and the UAC alerts finally stopped. But somehow a virus posing as an anti-malware scanner got installed anyways through my anti-virus guard and the UAC. Took me a whole day to finally clean it off my computer. I was close to just clean installing everything until I finally found the right combination of anti-virus tools to get rid of all traces of it.

...........Yep had this about 6 months ago from GameCopyWorld too..yeah it was a bitch to get rid of but I did

hotlazydaze 07/29/2010 4:22 PM
Hide
-0+

McAfee software is such badly written, intrusive rubbish that anyone who even considers using it on their computer without having read the thousands of forum posts by disgruntled users is a fool.

sliem 07/29/2010 5:14 PM
Hide
-0+

1) anyone who falls for this scam deserves it
2) real email from company will not include an attachment
3) why would you even want mcafee?
4) backup your precious data often and backup properly

r3t4rd 07/29/2010 5:27 PM
Hide
-0+

I wished they'd make this fake MaCaffee for OSX as well. I just want to see an acutal article on Toms with a picture of a worm inside an Apple. That would make my day. Apple users are more gulable.


TOM'S GUIDE AROUND THE WORLD

® 2010 BestofMedia All Rights Reserved.

Ads
Ads