{"id":508,"date":"2007-01-21T23:59:18","date_gmt":"2007-01-21T22:59:18","guid":{"rendered":"http:\/\/www.craigmurphy.com\/blog\/?p=508"},"modified":"2007-01-24T00:01:40","modified_gmt":"2007-01-23T23:01:40","slug":"confidence-tricks","status":"publish","type":"post","link":"http:\/\/www.craigmurphy.com\/blog\/?p=508","title":{"rendered":"Confidence Tricks"},"content":{"rendered":"<p>This seems to have been a weekend for computer support.  Today, Sunday, I found myself looking at an eMachines PC that refused to connect to the Internet using the https protocol.  The machine&#8217;s owner had already mentioned that he had ditched Norton Antivirus (and gone through a lot of pain trying to uninstall it) and had chosen WinAntiVirus as a replacement.  Why?  Well, a moderately reputable web-site &#8220;popped&#8221; something up that told him his computer needed &#8220;fixing&#8221;, a fake &#8220;you are infected&#8221; type of message.  WinFixer and WinAntiVirus would &#8220;fix it&#8221; for a small fee.  To all extents and purposes, it sounds fairly legit, you pay your money, you get a download link for a couple of products, you believe that you&#8217;re protected.  Except, these two products do little more than invite their friends (ad-ware, spyware, malware, etc.) in to play about on your computer.  From there, it goes from bad to worse.  And it&#8217;s not new as <a href=\"http:\/\/sunbeltblog.blogspot.com\/2005\/12\/another-fake-security-site.html\">this post<\/a> confirms.<\/p>\n<p>Luckily, I was able to uninstall WinFixer and WinAntiVirus, disable a whole raft of browser hijacks and clear down 115 items of ad-ware, spyware and malware.  Whilst I was there, I killed off all the remaining Norton services and lingering processes.  After a reboot and a re-scan, I was pleased to see the Windows XP shield appear at the bottom right &#8211; a clear sign that prior to my arrival something was &#8220;blocking&#8221; it thus preventing Automatic Updates from taking place.  WinFixer and WinAntiVirus may not have themselves been blocking Automatic Updates and other security-related activities (such as blocking scanning software), but they were certainly responsible for something getting on the computer that did.<\/p>\n<p>FWIW, the tools that I used to help me are: <a href=\"http:\/\/www.ccleaner.com\">Crap Cleaner<\/a>, <a href=\"http:\/\/www.spybot.info\/en\/index.html\">Spybot<\/a> and <a href=\"http:\/\/www.spywareinfo.com\/~merijn\/programs.php#hijackthis\">HijackThis<\/a>.<\/p>\n<p>On the premise that this is one of those &#8220;<a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=470\">how do you know<\/a>&#8221; scenarios, a piece of advice that I can offer is this:  <\/p>\n<p>If a pop-up window (or an advert within a web page) tells you that your PC is infected and offers a &#8220;clean up&#8221; solution, either ignore it or at least put it into your favourite search engine.  Google, for example, provides this advisory:<\/p>\n<p><img decoding=\"async\" id=\"image509\" alt=google.gif src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2007\/01\/google.gif\" \/><\/p>\n<p>Related links:<br \/>\n<a href=\"http:\/\/en.wikipedia.org\/wiki\/WinFixer\">http:\/\/en.wikipedia.org\/wiki\/WinFixer<\/a><br \/>\n<a href=\"http:\/\/www.spywareguide.com\/spydet_2731_winantivirus.html\">http:\/\/www.spywareguide.com\/spydet_2731_winantivirus.html<\/a><br \/>\n<a href=\"http:\/\/stopbadware.org\">http:\/\/stopbadware.org<\/a><\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/WinFixer\" rel=\"tag\">WinFixer<\/a>, <a href=\"http:\/\/technorati.com\/tag\/WinAntiVirus\" rel=\"tag\">WinAntiVirus<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Scam\" rel=\"tag\">Scam<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Hoax\" rel=\"tag\">Hoax<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Confidence+Trick\" rel=\"tag\">Confidence Trick<\/a>, <a href=\"http:\/\/technorati.com\/tag\/CCleaner\" rel=\"tag\">CCleaner<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Crap+Cleaner\" rel=\"tag\">Crap Cleaner<\/a>, <a href=\"http:\/\/technorati.com\/tag\/SpyBot\" rel=\"tag\">SpyBot<\/a>, <a href=\"http:\/\/technorati.com\/tag\/HijackThis\" rel=\"tag\">HijackThis<\/a>, <a href=\"http:\/\/technorati.com\/tag\/StopBadware\" rel=\"tag\">StopBadware<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This seems to have been a weekend for computer support. Today, Sunday, I found myself looking at an eMachines PC that refused to connect to the Internet using the https protocol. The machine&#8217;s owner had already mentioned that he had ditched Norton Antivirus (and gone through a lot of pain trying to uninstall it) and &hellip; <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=508\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Confidence Tricks<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,21],"tags":[],"class_list":["post-508","post","type-post","status-publish","format-standard","hentry","category-general","category-security"],"_links":{"self":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=508"}],"version-history":[{"count":0,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/508\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=508"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}