PC security

Tringa

Numpty of the Day'
Messages
6,194
Name
Dave
Edit My Images
Yes
On 24th June I received a message in my Inbox from the "IT White papers". The title of the message was "The Friday Five". As I was looking through my mail and deleting as I went along this message opened after I deleted the one above it. It purported to have information about IT issues and suggested I click on the link.

I know enough about unsolicited emails not to do that but the damage was already done. A window popped up saying 'XP Home Security 2012' had detected all sorts of nasties on my PC (I assume the name varies with the OS you are using).

These are usually no more than a nuisance but this one, in common with similar named variants from 2011 and I think 2010, is a difficult one. It disables all the security applications on your PC. If you have things like MalwareBytes and SpyBot S&D - forget them, they won't work. You can try renaming them, but in this instance, this did not work either. Online security scanners like FSecure also will not work. Web browsers are disabled and you are continually encouraged to buy the software that has allegedly detected a host of nasties.

It took me the best part of a day to deal with this one and get the machine back to normal.

I'm posting this now as today I have received another email from the same place(about one week later and also called the Friday Five) - this time I did not open it and it has gone, but just in case your email client automatically opens the next message after you have deleted the one you are reading, have a look at the list in your Inbox first and this email is there, delete it - do not open it.

As this one appeared in the Inbox, not Junk mail it could easily be taken to be OK.

Hope no one gets it, but if you do, do not pay anything. It is not the easiest of things to get rid of but it is possible.

Dave
 
It's common thing now days with "XP Home ..." or "Antivirus XP 2011" and so on. In most of the cases I had to deal with you would find .exe files in ApplicationData/AppData just sitting. You can always try to disable auto start-up in msconfig in Safe Mode or load through Mini XP via Hiren BootCD & delete those file. I tend to do disk clean-up while antispyware/antivirus software is running as it can pick-up dodgy files in temp folders.
Besides Hiren BootCD as useful tool I would suggest having AVG Rescue CD as well.
 
Back
Top