{"id":4220,"date":"2018-02-04T00:01:17","date_gmt":"2018-02-04T06:01:17","guid":{"rendered":"http:\/\/blog.zoha-islands.com\/?p=4220"},"modified":"2018-02-04T00:01:17","modified_gmt":"2018-02-04T06:01:17","slug":"microsoft-takes-on-the-scammers","status":"publish","type":"post","link":"https:\/\/zoha-islands.com\/blog\/microsoft-takes-on-the-scammers\/","title":{"rendered":"Microsoft Takes on the Scammers"},"content":{"rendered":"<p>Starting March 1, 2018, programs that attempt to coerce users into paying for dubious protection or PC performance \u201coptimization\u201d will be removed automatically by Microsoft Windows Defender Antivirus and other Microsoft security products. I can think of several rogues that will be hopefully out of business soon. Here&#8217;s what you need to know&#8230;<\/p>\n<h2>Bringing Down the Hammer on Scammers<\/h2>\n<h2><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-4229 alignright\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2018\/02\/hammer-300x196.jpg\" alt=\"\" width=\"371\" height=\"243\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/hammer-300x196.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/hammer-768x501.jpg 768w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/hammer.jpg 800w\" sizes=\"(max-width: 371px) 100vw, 371px\" \/><\/h2>\n<p>Microsoft has announced they are taking aim against programs like TotalAV, ScanGuard, PC Protect, and other \u201cfree security\/performance checkup\u201d scams.. Hallelujah! These programs are legion on the Internet, and like the three named above, many are often owned by the same devious company. <span id=\"ezoic-pub-ad-placeholder-111\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-medrectangle-4-0\" class=\"ezoic-ad ezfound\" data-google-query-id=\"CPjrlaLJidkCFQNgwQodlJALjg\"><\/span><\/p>\n<div id=\"crt-22\" class=\"ezflad-47\">They dominate the top spots in search results by paying the most to place their ads there. (I wish Google would do more to police this.) Every day, thousands of people who are trying to find free help for real PC problems instead get sucked into vortexes of FUD &#8211; \u201cFear, Uncertainty, and Doubt\u201d &#8211; and jerked around in expensive circles by con artists who follow a time-tested formula:<\/div>\n<ol>\n<li>Offer a free \u201ccheckup\u201d of a PC to find malware or causes of sluggish PC performance.<\/li>\n<li>Display a spinning circle or \u201cPlease wait, finding problems that could cause disaster\u201d messages<\/li>\n<li>Show the victim screen after screen of alarming \u201cwarnings\u201d about \u201cinfections\u201d and \u201cvulnerabilities\u201d that actually don\u2019t exist; the step above is just drama.<\/li>\n<li>Pressure the victim to pay for the \u201cpremium\u201d version of the useless software, which does not exist.<\/li>\n<li>If the victim buys, tell him the problem that doesn\u2019t exist is \u201cfixed\u201d but more problems remain.<\/li>\n<li>Pressure the victim again for even more money for a bogus \u201cfix\u201d to problems that don\u2019t exist.<\/li>\n<li>Repeat steps 5 &amp; 6 as long as they work.<br \/>\n<h2>Optimizing The Anti-Optimizer Strategy<\/h2>\n<p><span id=\"ezoic-pub-ad-placeholder-112\" class=\"ezoic-adpicker-ad\"><\/span>Microsoft first set some mild standards for \u201ccleaner and optimizer\u201d programs in February, 2016. All such programs had to do was tell a user specifically what problems it proposed to fix, and the program got a pass from Microsoft security products. Look how well that &#8220;honor system&#8221; approach worked for everyone! But now, Microsoft is getting serious, and dropping the hammer on these scam programs. <span id=\"ezoic-pub-ad-placeholder-117\" class=\"ezoic-adpicker-ad\"><\/span><\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/antimalware-support\/malware-and-unwanted-software-evaluation-criteria\" target=\"_blank\" rel=\"noopener\">Microsoft\u2019s evaluation criteria<\/a> is a document specifying unacceptable characteristics of programs scanned by Windows Defender and other Microsoft security programs. A new section spells out \u201cUnwanted behaviors: coercive messaging\u201d that will cause a program that exhibits it to be removed automatically from the user\u2019s machine. <img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-medium wp-image-4226\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2018\/02\/pay-up-300x300.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/pay-up-300x300.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/pay-up-150x150.jpg 150w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/pay-up.jpg 630w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Even when victims say, \u201cNo, I won\u2019t pay,\u201d a fake cleaner\/optimizer can still try to wring some money out of them by persuading or scaring them into answering a \u201cshort survey.\u201d Ostensibly, the victim\u2019s answers will only be used to help improve the \u201cfree\u201d program.<\/p>\n<p>But the deeper a victim goes into such surveys, the more personal and sensitive the questions become. You can easily be suckered into giving up bits of personal data that enable identity thieves to figure out the answers to your \u201csecret\u201d password recovery questions, or the actual passwords that you use, or the name of your bank, and other tools of ID theft.<\/p>\n<p>Microsoft\u2019s new \u201cunwanted behaviors\u201d include this sort of con, too. Programs that use such slimy tricks will be removed from PCs defended by Windows Defender beginning March 1.<\/p>\n<p>Also on the \u201cunwanted behaviors\u201d list are programs that suggest they are the only way to fix a problem; programs that set a deadline for the user to take action; programs that require the victim to download a file (which is probably a Trojan or virus); or sign up for a newsletter (so your email address can be sold to spammers). Such programs will be deleted automatically starting March 1.<\/p>\n<h2>Have You Encountered Rogue Software?<\/h2>\n<h2><\/h2>\n<h2><\/h2>\n<p><img decoding=\"async\" loading=\"lazy\" class=\" wp-image-4227 aligncenter\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2018\/02\/Scare-Malware-300x119.jpg\" alt=\"\" width=\"461\" height=\"183\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/Scare-Malware-300x119.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/02\/Scare-Malware.jpg 497w\" sizes=\"(max-width: 461px) 100vw, 461px\" \/>You can help in this fight against the scammers. If you encounter what you think may be rogue software, report the problem to Microsoft. You can <a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/filesubmission\" target=\"_blank\" rel=\"noopener\">anonymously submit a program<\/a> to Microsoft for analysis, and security researchers will analyze the file(s) to determine if they should be classified as malware. (Hmmm, this alone might be a good reason to download TotalAV.)<\/p>\n<p>If you are running Windows 10, Windows Defender is included and enabled, unless you&#8217;ve installed a third-party security tool. I&#8217;ve been critical of Defender in the past, but it seems to have improved greatly, and has some compelling new features. (See <a href=\"http:\/\/blog.zoha-islands.com\/is-windows-defender-enough-security\/\" target=\"_blank\" rel=\"noopener\">UPDATE: Is Windows Defender Enough Security?<\/a>)<\/p>\n<p>Microsoft&#8217;s announcement says that the &#8220;rogue removal&#8221; feature will be included in &#8220;Windows Defender and other Microsoft security products,&#8221; but they didn&#8217;t go into any detail about what those other products are, or if this protection will be extended beyond Windows 10. As more information becomes available, I&#8217;ll update you.<\/p>\n<p>I applaud Microsoft for taking direct action to protect Windows users from one of the most widespread threats online. I just wish they\u2019d done it back in February, 2016, instead of setting easily circumvented, toothless rules.<\/p>\n<p>Have A Great Week!<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Starting March 1, 2018, programs that attempt to coerce users into paying for dubious protection or PC performance \u201coptimization\u201d will be removed automatically by Microsoft Windows Defender Antivirus and other Microsoft security products. I can think of several rogues that will be hopefully out of business soon. Here&#8217;s what you need to know&#8230; Bringing Down &hellip; <a href=\"https:\/\/zoha-islands.com\/blog\/microsoft-takes-on-the-scammers\/\" class=\"more-link\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":4225,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[],"_links":{"self":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4220"}],"collection":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/comments?post=4220"}],"version-history":[{"count":0,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media\/4225"}],"wp:attachment":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media?parent=4220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/categories?post=4220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/tags?post=4220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}