Friday, January 15, 2010

Strength In Numbers.

RECAP:
So this week I've been dealing with a scammer posing as a representative of a charity asking me to cash checks I receive via FedEx. I am to send him the money via western union and Keep 10% for myself. I've gone over a few topics that can help you identify a scammer and some helpful resources on who to contact if you are a victim of internet fraud.

Finally. Getting results!
My work this week is starting to pay off. I contacted the moderator of an internet fraud Advisory group based in the UK. He gave me some insightful information and recommended that I do not cash any of these checks as it is undoubtedly part of a Nigerian Western Union scam. I have since sent him all of my email conversations and pictures of the fake checks I received. He will be posting this material on his web site and will be giving this material to the proper authorities.

I have also heard back from the Starlight Childrens Foundation. They have verified my findings with the following email:

Hi
I cannot verify the legitimacy of this job Im afraid. We have had quite a few of these emails and there are no jobs going at Starlight. Please ignore any emails that claim to be from Starlight UK. We don't advertise on Craiglist and any correspondence from ourselves would come from an email address ending @starlight.org.uk.
Apologies for any inconvenience caused and thank you for alerting us to this.

Kind Regards

Cara Williams

PA to Neil Swan, CE

Starlight Children's Foundation | Macmillan House | Paddington Station | London | W2 1HD

Unfortunate but True....
Its unfortunate that this scammer is dragging this charities good name through the mud. It also seems that I am not the only person the scammer has come in contact with. Unfortunately, it is likely that the scammer has already stolen thousands of dollars from legitimate business like the ones printed on the checks I received lately. These people now have the horrible task of spending months if not years fixing their credit with the US government. It takes a great deal of work to build a business from the ground up and tragically that means very little to scammers like this one.

How Can You Help?
The next time you encounter an internet scammer handing out promises of fast money, report it immediately to proper authorities. The best way to fight internet crime is prevention. Try to stop yourself from glancing over suspicious posts. Don't tell yourself "Disater avoided, no longer my problem". You can easily stop the REAL crimes happening on the internet with just a few minutes informing the right people.

I'd like to change gears for a moment.....
I stated yesterday that I would address a piece of malware called Malware Defense that has been circulating the internet lately. I've personally come in contact with this malware on several occasions and ended up saving my friends lots of headache and money not having to take their PC to a shop.

Malware, Spyware, Virus's whats the difference....
Malware is a general term for malicious software designed to damage or compromise the machine it installs itself on. Malware is a combination of Virus and spyware so no difference really. In my book a virus is a virus no matter how sophisticated.

So what does it do?
Malware Defense infects your computer by prompting you in one of several ways:

1)While browsing a web page you may get a window telling you that your computer is in danger and you should download System protection offered by "us". If you click anywhere in the window Malware Defense installs on your computer.

2)Another way Malware Defense tricks you is by posing as a windows security center window asking you to update your virus protection. Once you do Malware Defense installs itself.

3) Finally, the last way of infection is actually applicable to any virus, spyware, or malware. If you have downloaded a file, inserted a USB drive or other writable medium, and it contains a copy of the malware, it will automatically install on your system.

Once installed it will look something like this:



After running for a few days, Malware Defense will begin to delete your antivirus and spyware protection. If left unchecked Malware defense will damage a file called atapi.sys, a system file windows absolutely needs to run successfully. You will continually receive blue screen after blue screen when attempting to boot normally or in safe mode.

That sucks! How do I get rid of it?
I stated at the beginning of my blog THERE IS NO REPLACEMENT FOR A TRAINED TECHNICIAN. This tool Ill be discussing is effective at removing harmful software. However, if you do not have a technical background, I only recommend using the Techfu Technique! I mention.

Anyway...Removal.
I found a great site that includes a detailed description and tutorial about how to remove this virus in much the same way I did. DO NOT PERFORM AN UNINSTALL OF MALWARE DEFENSE. It will just make the problem worse.

In the tutorial they uses a free program called MalwareBytes Anti-Malware or MBAM to identify Malware Defense in several places your normal virus scanner would not. You can use malware bytes free of charge and it's very simple to navigate around in this program.

Tech Fu Technique! After downloading and installing this on your computer, a "once a week" scan with MBAM can prevent a good deal of harmful software from wreaking havoc on your computer. Very easy to start a scan. Just click the Button "perform full scan" and click "scan". It takes about 20min to an hour to complete depending on the speed of your computer and amount of files on your computer.

For those with a technical background MBAM does a complete Registry Scan in-addition to its file scan much like spybot. I've found MBAM's heuristics to be more effective than Spybot as it discovered a few pieces of Spyware and Malware Defense that Spybot did not. MBAM was also very effective at identifying and deleting the rootkits associated with Malware Defense which allow it to re-propagate itself once completely deleted from your system. I wouldn't go as far to say this is a replacement for spybot. But its a nice addition to the toolkit. Check this interesting article.

Thanks for reading!





No comments:

Post a Comment