Yesterday I was called to one of my clients to remove a fake antivirus program. So I stopped by and cleaned the machine, manually then it was scanned with malware bytes which removed a few more traces. Completely normal. Until this morning when I got a call back saying it’s back. So I stopped by and there was a website with fake popup from us-scann(dot)com. Google has nothing on them, yet. So I’m blacklisting the domain in their dns and running another scan then another manual look.
It has been my observation over the past few weeks that thee has been a sharp increase in these fake av’s. So be on the lookout and make sure you and your employees KNOW what programs are on your machine.
Posted under Information/Advisories
This post was written by admin on January 21, 2010
