<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacyscams</title>
	<atom:link href="http://hijack-this.co.uk/category/scams/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:31:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Fake Microsoft Malicious Software Removal tool</title>
		<link>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/</link>
		<comments>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 16:57:37 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=311</guid>
		<description><![CDATA[var uri = 'http://impgb.tradedoubler.com/imp?type(img)g(18352020)a(1262921)' + new String (Math.random()).substring (2, 11); document.write(''); It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &#38; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading This total piece of scamware [...]]]></description>
			<content:encoded><![CDATA[<p>It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &amp; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading<br />
This total piece of scamware is designed to imitate the genuine MMSRT &amp; has the usual fake detections &amp; then entices you buy the latest rogue scamware Shield EC Antivirus which our good friends <a href="http://sunbeltblog.blogspot.com/2010/07/shield-ec-rogue-security-product-that.html" target="_blank">Sunbelt Software have blogged about.</a><br />
The last screen clearly shows that they want you to buy this useless scamware</p>

<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1/' title='Rogue_1'><img width="150" height="106" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1-150x106.png" class="attachment-thumbnail" alt="Rogue_1" title="Rogue_1" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1a/' title='Rogue_1A'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1A-150x137.png" class="attachment-thumbnail" alt="Rogue_1A" title="Rogue_1A" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1b/' title='Rogue_1B'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1B-150x137.png" class="attachment-thumbnail" alt="Rogue_1B" title="Rogue_1B" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1c/' title='Rogue_1C'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1C-150x137.png" class="attachment-thumbnail" alt="Rogue_1C" title="Rogue_1C" /></a>

<p>The installer for this piece of malware is detected by several Antiviruses currently as shown on this <a href="http://www.virustotal.com/file-scan/report.html?id=73b0e3dc9a74f97892194efe47886957232a2e72374a0a57bccb64b81bff29e6-1281535897" target="_blank">Virus Total </a>report page</p>
<p>If you are unfortunate to be infected by this piece of scamware, it can be difficult to remove. Don&#8217;t fall for all the other scams on the net saying you need to buy other software to remove it. Ask for help on our malware cleaning forum <a href="http://thespykiller.co.uk" target="_blank">http://thespykiller.co.uk</a></p>
By the time  your rss reader get this post here is <strong> 1 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Misleading Google adverts</title>
		<link>http://hijack-this.co.uk/2010/06/misleading-google-adverts/</link>
		<comments>http://hijack-this.co.uk/2010/06/misleading-google-adverts/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 13:15:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=298</guid>
		<description><![CDATA[Many of us in the security community are concerned about misleading adverts. This one in particular has started to make waves within the wider Technical support community. It is frequently displayed on blogs &#38; forums offering free technical support and appears designed to fool a user into thinking that they are getting Microsoft Technical Support, [...]]]></description>
			<content:encoded><![CDATA[<p><br />
Many of us in the security community are concerned about misleading adverts. This one in particular has started to make waves within the wider Technical support community. It is frequently displayed on blogs &amp; forums offering free technical support and appears designed to fool a user into thinking that they are getting Microsoft Technical Support, when in fact the link goes to a site that makes you pay for help and assistance  that has absolutely no connection to Microsoft as a company<br />
The advert below is the one in question. Click on it to get a full size image<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers.png"></a></p>
<p style="text-align: center;"><a href="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers.png"><img class="size-medium wp-image-299 aligncenter" title="answers" src="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers-300x36.png" alt="" width="300" height="36" /></a></p>
<p>We all understand that adverts are a necessity in todays world to defray costs in running a website and an occasional rogue or misleading advert will slip through. I use Google adsense here on this blog and hope that all the adverts will be honest and above board. All webmasters, blog owners and Forums admins do need to keep an eye open for such adverts. Google must take a high degree of responsibility and start to police its advertising system more closely and weed out these deliberately misleading adverts.</p>
<p>The Company Justanswer.com who publish the adverts should be ashamed of themselves and I ask all readers to avoid that company and any others that use such underhand tactics to drive vulnerable visitors to their site.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/06/misleading-google-adverts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI credit card scam spam</title>
		<link>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/</link>
		<comments>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 15:51:36 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=272</guid>
		<description><![CDATA[The lengths that scammers will go to try to convince a possible victim is quite unbelievable The following email dropped in my spam box I really can&#8217;t believe anyone will think the FBI issue or verify credit cards/ATM cards &#38; charge you $95 insurance fee for the privilege Once again the advice is, if it [...]]]></description>
			<content:encoded><![CDATA[<p>The lengths that scammers will go to try to convince a possible victim is quite unbelievable<br />
The following email dropped in my spam box</p>
<p>I really can&#8217;t believe anyone will think the FBI issue or verify credit cards/ATM cards &amp; charge you $95 insurance fee for the privilege</p>
<p>Once again the advice is, if it doesn&#8217;t look right, then it isn&#8217;t right so delete these scam emails and don&#8217;t reply to them or phone the numbers given. All that will do is get you a big phone bill from dialling a premium rate international phone number</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/12/fbi_cc.PNG"><img class="alignnone size-medium wp-image-273" title="fbi_cc" src="http://hijack-this.co.uk/wp-content/uploads/2009/12/fbi_cc-300x234.PNG" alt="fbi_cc" width="300" height="234" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of fake shopping sites</title>
		<link>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/</link>
		<comments>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 10:55:16 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=261</guid>
		<description><![CDATA[With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &#38; credit card details. A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can [...]]]></description>
			<content:encoded><![CDATA[<p><br />
With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &amp; credit card details.</p>
<p>A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can be sure that thousands of people have and the same scam will be applied to just about every well known online shopping site this season.</p>
<p>The email looks quite believable<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email.PNG"><img class="alignnone size-medium wp-image-262" title="littlewoods_email" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email-300x258.PNG" alt="littlewoods_email" width="300" height="258" /></a></p>
<p>The website if you follow the link looks exactly like the real Littlwoods shopping site Account sign in page <strong>EXCEPT</strong> that the real Littlewwoods or ALL reputable shopping sites will have a Padlock icon and the  site address will start with<strong> HTTPS</strong> and the address bar will turn green to show that you are on a secure site</p>
<p>This screenshot shows the fake site and I have blanked out the address for safety reasons<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web.PNG"><img class="alignnone size-medium wp-image-263" title="littlewoods_web" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web-300x231.PNG" alt="littlewoods_web" width="300" height="231" /></a></p>
<p>These show how a genuine site will appear in Internet Explorer 8 on left and Firefox on right. Both show the padlock icon and a green safe address bar. A genuine shopping site will always start <strong>HTTPS</strong> to show a secure site when you are asked to put in any details. The front page of the site might be a normal http:<br />
Unfortunately a lot of well known shopping sites haven&#8217;t yet signed up to the Extended Valuation green bar very secure system yet so watch for the closed padlock and HTTPS in the address bar to show a secure site. In Firefox browser the closed padlock is on the bottom right hand corner of the page, not in the browser address bar </p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE.PNG"><img class="alignnone size-medium wp-image-264" title="littlewoods_IE" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE-300x193.PNG" alt="littlewoods_IE" width="300" height="193" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods.PNG"><img class="alignnone size-medium wp-image-265" title="real_littlewoods" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods-300x232.PNG" alt="real_littlewoods" width="300" height="232" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
By the time  your rss reader get this post here is <strong> 2 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WOW  wowmatrix keylogger</title>
		<link>http://hijack-this.co.uk/2009/11/wow-keylogger/</link>
		<comments>http://hijack-this.co.uk/2009/11/wow-keylogger/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 11:00:42 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[world of warcraft]]></category>
		<category><![CDATA[wowmatrix]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=227</guid>
		<description><![CDATA[I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version [...]]]></description>
			<content:encoded><![CDATA[<p><br />
I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games<br />
Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version that downloads false addons &#038; tweaks and installs them leaves you open to a lot of problems. </p>
<p>The advert on google looks like a search listing and it is only apparant that it is a sponsored listing or advert on close inspection</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix.PNG"><img class="size-medium wp-image-228 aligncenter" title="wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix-300x148.PNG" alt="wowmatrix" width="300" height="148" /></a><span id="more-227"></span></p>
<p>if you look at the screenshots of the 2 sites, you will see that there is very little difference between them and an unwary visitor can soon get infected</p>
<p>Don&#8217;t get caught out by it and get your passwords stolen. The downloads on the fake site are recognized by several antiviruses as a password stealer and downloads lots of other trojans and malware</p>
<p>the genuine site is on the left, the fake site on the right</p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix.PNG"><img title="genuine_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix-300x297.PNG" alt="genuine_wowmatrix" width="300" height="297" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1.PNG"><img title="fake_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1-300x291.PNG" alt="fake_wowmatrix" width="300" height="291" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/wow-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Lottery Spam</title>
		<link>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/</link>
		<comments>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 11:01:04 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=221</guid>
		<description><![CDATA[We seem to have a new batch of the Microsoft lottery spam emails again These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way) DO NOT fall [...]]]></description>
			<content:encoded><![CDATA[<p>We seem to have a new batch of the Microsoft lottery spam emails again</p>
<p>These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way)</p>
<p>DO NOT fall for the scam &amp; try to ring the 070240****** number . it is a premium rate number that will have along recorded message on it and cost you £0.50 per minute</p>
<p>You won&#8217;t get any money from these scammers but they will get money from you</p>
<p>I have blanked out the full email address and phone number from the image to save the unwary</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam.PNG"><img class="aligncenter size-medium wp-image-222" title="MSlotteryscam" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam-247x300.PNG" alt="MSlotteryscam" width="247" height="300" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
