Security warning: Security Master AV

Discussion in 'Technical, security and bug reports' started by NotAdmin, Jun 16, 2010.

  1. NotAdmin

    NotAdmin Administrator

    There's apparently a new virus on the block, and it's a particularly tricky one, as it poses as an anti-virus tool. There's quite a few recent posts about it floating around on the Internet, so we figured we would warn you through this channel as well.

    There's a piece of software called "Security Master AV", which poses as an anti-virus package (and has been designed in such a way that it closely resembles the Microsoft Security tools), that will flash fake warnings about virus infections at you. The idea is that an unsuspecting user will think their normal anti-virus might have missed something. The program will make it look as if it offers better protection, and if as user falls for it and installs it, it will drop a bunch of files on their harddrive, start scanning, and then flag the newly dropped files as horrible nasty viruses.

    [​IMG]

    You can recognise the fake anti-virus message by the name of the tool, as shown and highlighted in the screenshot above.

    Naturally, the program will state it will not be easy to remove the viruses, but luckily, if the user upgrades to the full version of the software, the world will be safe once again. Truth is, if the user does fall for it, their money is gone, and this new anti-virus package itself is actually... a virus/trojan.

    It will take steps to prevent you from being able to remove it, including renaming specific Windows programs that are meant to get rid of malware, and it will also hijack your browser so you will end up using a different search engine than normal. The idea there is most likely to serve you ads.


    Removal instructions can be found here:

    http://www.bleepingcomputer.com/virus-removal/remove-security-master-av

    Basically, you will have to download and run MalwareBytes to get rid of all files dropped on your system by the virus. Finally, you will have to undo the damage to your hosts-file (which is how the browser-hijacking was done). In the case the virus blocks you from obtaining MalWareBytes, there's even a workaround offered as well, which tricks the virus by renaming the removal tool.


    Should you have fallen for the scam, call your bank, and have them reverse the payment. For your own safety, have your credit card blocked and ask for a replacement one to prevent these criminals from using your card. Should you have used a common password (meaning you use it for other purposes as well) when you bought the software, please change your passwords immediately.
     
  2. Shadowsong

    Shadowsong Collateral Damage

    Thanks for the heads-up. Sounds like a nasty piece of work indeed.
     
  3. Sadly there are quite a few fake anti-virus / anti-malware programs out there that pop up in your face like this and claim that your system is insecure and it has found dozens of dodgy files.

    They are all malware themselves, all looking to get into your system and turn it into a spam-bot and/or steal information and/or do something else that isn't good for you or your system.

    Always have reputable anti-virus and anti-malware programs installed, keep up with windows updates, and keep other programs and plug-ins (like flash) updated too - there's flaws in everything these days.

    Take care out there,
    Deathifier
     
  4. Corrianna Trina Xenophage

    Corrianna Trina Xenophage Trained "Psycho&a mp; amp;quot;trop i

    Simple rule to apply here...

    If its not YOUR antivirus program even if it is not known to be the best DO NOT try a new AV program in this way.

    Close that window or what I usually do is unplug my net connection THEN close out the browser so no redirects can occur or any other funky stuff.

    Then if you desire to change your antivirus do so on your terms not a warning.
     
  5. Looks like a new wrapper on antivirus 2009. :(
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.