Issue No. 72July 2018


A New Type of Malware

A method that has been gaining popularity by tech support scammers is to spread malware with the sole purpose of locking the user out of their own computer. We call this type of malware screenlockers and the installers are detected as Trojan.TechSupportScam. They may look like a BSOD (Blue Screen Of Death) or a warning that you are using illegal software (asking for a registration key). The malware is offered as part of a bundle or posing as an installer for something else.

The ones that look like a BSOD usually have a telephone number on them that belongs to the scammers outfit. Once you call that number they will tell you a trick to get rid of the BSOD to gain your trust, but of course the trick was built into the program for that reason.

The type asking for a registration number, usually has a telephone number as well, but often they come with a few links that will open sites with popular remote assistance/desktop software like TeamViewer, LogMeIn, Ammy Admin, Supremo, and others. In these cases, the scammers will ask you to install that software and give them your access code, so they can “repair” your computer. Selling you overpriced solutions and obtaining your personal information is the real goal here.

