Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

February 27th, 2010, 12:17 GMT · By

VirusTotal Brand Abused to Push Scareware

SHARE:

Adjust text size:


VirusTotal targeted by scareware distributors
Enlarge picture
The name of the popular file analysis service VirusTotal is being abused by cyber-crooks to infect users with scareware. A recent forum spam campaign tries to trick people into visiting a malicious website hosted at virus-total.in.

Security researchers from Sophos reported a spam run promoting the rogue virus-total domain, as a private message on a forum. The message employs scare tactics in order to frighten users into visiting the scareware-pushing website.

"There are viruses’ activities from your computer! Highly recommend you to scan your computer for malicious and potentially unwanted software. If you do not follow this, I will have to make a complaint to your Internet Service Provider with attached log file (your IP address, etc.). If you want to find a report about your computer’s security and solve every problem with it, please click here: [malicious url] This is an online service that you can use for free spyware removal," the message reads.

This attack clearly targets VirusTotal.com, a popular free service which allows users to scan suspicious files with over 40 antivirus engines and other tools. Julio Canto, VirusTotal's project manager, issued an alert about the rogue virus-total.in website via Twitter.

The site displays bogus security warnings and fake antivirus scans to unsuspecting visitors, tricking them into installing a scareware program called SecurityTool. Rogue security programs such as these are commonly used by cyber-criminals to charge money for useless licenses and steal credit card details.

"An unfortunate side effect of a scam like this is that the real VirusTotal could start to receive emails from irate victims of the fake site claiming they’ve 'infected my PC' – fingers crossed it doesn’t get to that stage. Remember: the REAL domain for VirusTotal is Virustotal.com. Don’t fall for this scam!" Sunbelt's Chris Boyd advises.

Another unusual aspect of this attack is the threat of filing a complaint with a user's ISP about the virus activity alleged in the spam message. This statement comes at a time when ISPs have announced initiatives to identify compromised computers on their networks and take proactive measures to clean them.

TELL US WHAT YOU THINK:

2,726 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Beware of Tilikum Killer Whale Search Results

Clooney and the Oscars, a Bad Security Mix

Bill Cosby Death Rumor Used to Push Scareware

Google Groups Riddled with Malicious Links

German Government to Help Rid Computers of Malware

READER COMMENTS:


Comment #1 by: Dyrmyk on 27 Feb 2010, 16:44 UTC reply to this comment

The same thing happened with my friend's computer, only with a different website where a program installed itself on to the computer and completely took it over not letting any programs run at all. all it did was cancel all operations and said the program has been infected, the so called anti virus program only allowed internet explorer to run and it redirected itself to the company site which is Http://avgroupwebsite.com.
I had to reformat my friend's hard drive and I am restoring it back to normal right now.
I am going to send a team of internet authorities after these people and anyone who has been a victim of that program and site can join me. What these people are doing is also illegal and they must be stopped.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM