Windows Debug Center Harms PC Users with Its Fake Antivirus Program

Computer users muddling through a situation where they suspect their PC is infected with malware often look for the easiest and quickest solution. Some PC users may find refuge in discovering that a program named Windows Debug Center is present on their computer, so they attempt to use it for removing malware. Unfortunately, performing those actions will end up in disaster by Windows Debug Center failing to remove malware.

Windows Debug Center is a fake security application. As explained by many new removal reports, such as the Windows Debug Center removal report found on EnigmaSoftware.com, Windows Debug Center is not a viable antivirus program nor will it activate after purchasing. Just like previously identified rogue antivirus programs such as Windows Defending Center, Windows Debug Center will automatically execute when Windows boots. This ultimately makes it difficult to remove or un-install Windows Debug Center.
 

http://www.prleap.com/pr/185866/

BBB ALERT: Bogus Emails Claiming to Be From BBB

For the sixth time in recent months, phishing scams using The Better Business Bureau’s name have been sent in an attempt to lead recipients to a site that carries a malicious virus.

The most recent rash of bogus emails carry subject lines that read either ”The Better Business Bureau Investigation,” “The Better Business Bureau Complaint, ” or ”The Better Business Bureau Dispute Resolution.” The e-mails are fraudulent; even the BBB of North Alabama has been receiving these bogus emails.

The email with the subject line “The Better Business Bureau Investigation” contains the following text:

http://whnt.com/2012/03/30/bbb-alert-bogus-emails-claiming-to-be-from-bbb/

Cyber criminals launch their latest bogus Microsoft security alert

Computeractive has uncovered a sophisticated phishing attack that fools people into downloading malicious software by mimicking a genuine Microsoft Windows security alert.

A variation on rogue anti virus software, the email includes a link to a phishing website, which takes the victim to a fake website. The words "You are here because one of your friends have [sic] invited you here. Page loading, please wait…" is shown and a fake Microsoft startup screen loads.

A menu bar appears and says "Microsoft Security Alert 2012 has found critical process activity on your PC and will perform fast [sic] scan of systems files."

It then appears to the victim as if their computer is being scanned in real time. A Windows security alert menu will then pop up with ‘Remove All’ or ‘Cancel’.

If the person clicks Remove All, a file called setup.exe is downloaded, which infects the PC with a Trojan that harvests people’s email contacts.

A video of the attack has been put online by a Computeractive team member.

 

pcAnywhere users are at great risk. Symantec recommends disabling to prevent a malicious attack.

pcAnywhere users are at great risk. Symantec recommends disabling to prevent a malicious attack. 

Symantec, maker of pcAnywhere, warns against malicious attacks that may occur due to a 2006 security breach in which the source code to the pcAnywhere product and other Symantec products was stolen by a hacker. Symantec recommends customers immediately disable the software to prevent malicious attacks. Removal of the software is the best course of action. 

pcAnywhere provides remote access and remote desktop functionality, however it does not support two-factor authentication that is necessary for a payment environment to meet PCI DSS compliance.  

For more information on this Symantec pcAnywhere security issue, please reference the following white paper published by Symantec on Monday, January 23, 2012: 

Massive Android malware op may have infected 5 million users

Computerworld – The largest-ever Android malware campaign may have duped as many as 5 million users into downloading infected apps from Google’s Android Market, Symantec said today.

Dubbed "Android.Counterclank" by Symantec, the malware was packaged in 13 different apps from three different publishers, with titles ranging from "Sexy Girls Puzzle" to "Counter Strike Ground Force." Many of the infected apps were still available on the Android Market as of 3 p.m. ET Friday.

http://www.computerworld.com/s/article/9223777/Massive_Android_malware_op_may_have_infected_5_million_users?source=CTWNLE_nlt_pm_2012-01-27

Build Up Your Phone’s Defenses Against Hackers

Technology experts expect breached, infiltrated or otherwise compromised cellphones to be the scourge of 2012. The smartphone security company Lookout Inc. estimates that more than a million phones worldwide have already been affected. But there are ways to reduce the likelihood of getting hacked — whether by a jealous ex or Russian crime syndicate — or at least minimize the damage should you fall prey.

http://www.nytimes.com/2012/01/26/technology/personaltech/protecting-a-cellphone-against-hackers.html

Scareware Distributors Start Targeting Smartphone Users, Experts Warn

Scareware distributors are targeting smartphone users who search the Web for popular mobile apps, experts from antivirus vendor Kaspersky Lab warn.
 

Rogue programs that masquerade as antivirus software have been used to scam computer users for many years. The money generated by such schemes is regularly used to fund other illegal activities.

The high profitability of scareware has pushed some cybercriminal gangs into previously unexploited markets, like those of Mac computers and now smartphones.

According to Kaspersky Lab senior malware analyst Denis Maslennikov, mobile malware creators are using black hat search engine optimization (BHSEO) to poison Google search results for popular mobile apps like Opera Mini with malicious links.

http://www.pcworld.com/businesscenter/article/247194/scareware_distributors_start_targeting_smartphone_users_experts_warn.html

PSS Critical Security Alert – New Worm: Nachi, Blaster-D, Welschia

PSS Security Response Team Alert – New Worm: Nachi, Blaster-D, Welchia

SEVERITY: CRITICAL
DATE: 08/18/2003
PRODUCTS AFFECTED: Windows 2000 and XP, Internet Information Services 5.0

************************************************** ********************

WHAT IS IT?
A new worm is spreading in the wild. The Microsoft Product Support Services
Security Team is issuing this alert to advise customers to be on the alert
for this virus as it spreads in the wild. Customers are advised to review
the information and take the appropriate action for their environments.

IMPACT OF ATTACK: Network Propagation, Patch Installation

TECHNICAL DETAILS:
Similar to the earlier Blaster worm and its variants, this worm also
exploits the vulnerability patched by Microsoft Security Bulletin MS03-026,
and instructs target systems to download its copy from the affected system
using the TFTP program.

In addition to exploiting the RPC vulnerability patched by Microsoft
Security Bulletin MS03-026 this worm also uses a previously patched
vulnerability in Microsoft Security Bulletin MS03-007 directed at IIS 5.0.

http://www.mombu.com/microsoft/scripting-virus-discussion/t-pss-critical-security-alert-new-worm-nachi-blaster-d-welschia-11328463-new.html

 

Phony Bank of America Alert Emails Link to Malware

Be sure to hover your mouse over any links in Bank of America emails to verify they will lead you to the proper place.

Cybercriminals are doing their best to imitate emails sent by Bank of America to notify customers of important account alerts in order to spread malware.

The spam email closely resembles legitimate BofA emails and is void of any obvious spelling or grammar mistakes – characteristics that typically tattle-tale on spam emails the moment they’re opened.

http://www.hyphenet.com/blog/2011/12/28/phony-bank-of-america-alert-emails-link-to-malware/