When Christiane saw the notice that her email was infected with viruses, she panicked. A translator, she relies on her laptop for work.
“I thought it was going to break down immediately,” she says. With that in mind, she downloaded anti-virus software advertised in the warning window. What she didn’t know was that the warning was as fake as the protective software. She had become a victim of scareware.
Scareware, as the name implies, is a business based on fear. Criminals spread fear with fake virus warnings and then offer expensive, but useless, software to get rid of the reported viruses. So far, only one cure has been discovered to combat scareware: skepticism.
“The software is free, but is usually comes with incitements to buy an expanded version for 30 to 40 euros ($41 to $55),” explains Candid Wueest, a virus expert with the company Symantec. These scareware problems essentially solve a problem that didn’t exist without them.
Scareware rackets are fairly widespread. A survey by the German Federal Office for Information Security (BSI) found that 60 per cent of respondents are aware of the problem and that about 9 per cent had been affected. Research by security software companies came up with similar results, but noted that it was helping their business. German computer magazine c’t wrote of a “multi-million dollar business.”
Cybercriminals tend to use security gaps in Web sites to distribute their scareware.
“The attackers manage to insert a small script at the bottom of the page,” explains Wueest. If surfers go to that site, they get the warning window. The criminals are sophisticated enough to insert their warnings onto reputable Web sites that lack adequate security. Christiane was researching with an online dictionary when her warning popped up.
Some users create the avenues criminals use to find them. Anyone who fails to regularly…