What is therightwaytofindplayering[.]pro?
therightwaytofindplayering[.]pro is a deceptive site running a scam claiming that Adobe Flash Player is outdated and must be updated immediately. In fact, this site promotes a fake Flash Player updater. These updaters are commonly used to proliferate untrustworthy and malicious content (e.g. trojans, ransomware and other malware).
At the time of research, the updater was bundled with the following untrusted applications: AnonymizerGadget version 4; CodecsSetup version 6.3.; nproject version 1.3, and; WebDiscover Browser 4.28.2.
Most users do not access scam web pages (including therightwaytofindplayering[.]pro) intentionally - they are redirected to them by intrusive advertisements or Potentially Unwanted Applications (PUAs) already infiltrated into the system.
There are several variants of this scam run on therightwaytofindplayering[.]pro, though they are thematically identical. Visitors to the deceptive web page are presented with several pop-up windows, which claim that the Adobe Flash Player is out of date and urges them to update it.
The first pop-up is identical to scam variants run on Google Chrome, and Mozilla Firefox. It states that Flash Player should be updated, as the current version is outdated. The aforementioned variant displays another window, which repeats the message and adds that these updates will only take a number of seconds to install and require no restart following installation.
The Firefox version goes into further detail, informing users that Adobe Flash Player is an essential browser plug-in, enabling them to view media such as audio, video, animation and play online games. Since the current version supposedly does not have the latest security update, it has been blocked.
The scam opened in Chrome browsers, overlays its previous window with another pop-up, which also makes bogus claims concerning a lack of the latest security updates for Flash. This same pop-up is also displayed in Firefox. Most these pop-ups have buttons, which initiate download of the bogus updates.
installing them will not update Adobe Flash Player - instead, users will inadvertently allow untrustworthy/malicious content onto their devices (e.g. AnonymizerGadget version 4, CodecsSetup version 6.3., nproject version 1.3 and WebDiscover Browser 4.28.2).
You are strongly advised to only update software with tools/functions provided by legitimate developers. Downloading/installing third party updaters (promoted by scam sites or obtained from other sources) is highly likely to lead to serious issues.
PUAs force-open various deceptive/scam, untrustworthy/rogue, compromised and malicious websites, however, they can have other dangerous capabilities. Adware-type PUAs deliver intrusive ads, which diminish the browsing experience, cause redirects to harmful web pages and can even download/install software without users' consent or knowledge.
PUAs classified as browser hijackers modify browsers, limit/deny access to settings and promote fake search engines. Note that these apps rarely seem suspicious and can infiltrate systems under the guise of "useful" products. Yet, the features promised are rarely operational. All PUAs can perform data-tracking.
They monitor browsing activity (URLs visited, pages viewed, search queries typed, etc.) and gather users' personal information (IP addresses, geolocations and other details). The only purpose of unwanted applications is to generate revenue for the developers, at the expense of users (e.g. through misusing the collected data).
In summary, PUAs can lead to browser and system infiltration/infections, financial loss, serious privacy issues and even identity theft. Due to these risks, you are advised to remove all dubious applications and browser extensions/plug-ins immediately upon detection.
|Threat Type||Phishing, Scam, Social Engineering, Fraud.|
|Fake Claim||Scam claims that Adobe Flash Player is outdated.|
|Distributed Unwanted Apps||AnonymizerGadget version 4, CodecsSetup version 6.3., nproject version 1.3, WebDiscover Browser 4.28.2|
|Detection Names (fake updater "VideoCodecSetup.exe")
||Avast (Win32:AdwareX-gen [Adw]), BitDefender (Trojan.GenericKD.42264355), ESET-NOD32 (Win32/Adware.RK.AZ), Fortinet (Riskware/RK), Full List Of Detections (VirusTotal)|
|Symptoms||Fake error messages, fake system warnings, pop-up errors, hoax computer scan.|
|Distribution methods||Compromised websites, rogue online pop-up ads, potentially unwanted applications.|
|Damage||Loss of sensitive private information, monetary loss, identity theft, possible malware infections.|
|Malware Removal (Windows)||
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.
Other popular models include warnings that the system is at risk / infected (e.g. "Your Windows 10 is infected with 5 viruses!", "VIRAL ALARM OF MICROSOFT" etc.), fake prizes/awards (e.g. "Dear [ISP name] user, Congratulations!", "YOU ARE THE CHOSEN!" etc.), unbelievable offers (e.g. "Get the new iPhone 11 Pro", "Randomly selected to test the new iPhone" etc.) and many others.
The only purpose of these schemes is to generate profit for the designers by deceptively encouraging users to download/install or purchase untrustworthy/malicious content, revealing their personal information (e.g. identity, banking, credit card details, etc.), calling expensive and fake technical support numbers, making monetary transactions (e.g. fake fees, payments, etc.) and so on.
How did potentially unwanted applications install on my computer?
PUAs proliferate via the download/install set-ups of other software. This deceptive marketing technique of pre-packing regular products with unwanted or malicious programs is called "bundling". Rushing download and installation processes (e.g. skipping steps and sections, etc.) increases the risk of unintentionally allowing bundled content onto system.
Some PUAs have "official" promotional web pages, from which they can be downloaded. Intrusive advertisements also proliferate these applications. Once clicked, they can execute scripts designed to stealthily download/install PUAs.
How to avoid installation of potentially unwanted applications
You are advised to research all products, prior to download/installation and/or purchase. All downloads should be performed from official and verified sources only. P2P sharing networks (BitTorrent, eMule, Gnutella, etc.), free file-hosting sites and other third party downloaders are classed as untrustworthy and should be avoided.
When downloading/installing, read the terms, study all available options, use the "Custom/Advanced" settings and opt-out of supplementary apps, tools, functions and so on. Intrusive ads often seem normal and innocuous, however, they redirect to dubious pages (e.g. gambling, pornography, adult-dating and others).
If you encounter these ads/redirects, inspect the device and remove all suspicious applications and/or browser extensions/plug-ins without delay. If your computer is already infected with PUAs, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate them.
Text presented in the initial pop-up window:
Adobe Flash Player recommends: Update the latest version of Flash Player. Your current Adobe Flash Player version is out of date.
Screenshot of the second pop-up displayed:
Text presented in this page:
"Adobe Flash Player" is out of date
The version of "Adobe Flash Player" on your system does not include the latest security updates and has been blocked.
Updating takes a few seconds and no restart needed after installation.
Update Download Flash...
Screenshot of the pop-up overlaying the previous one:
Text presented in this pop-up:
"Adobe Flash Player" is out-of-date
The version of this plug-in on your computer doesn't include the latest security updates. Flash cannot be used until you download an update from Adobe.
Update Download Flash...
The appearance of therightwaytofindplayering[.]pro scam on Google Chrome (GIF):
The appearance of therightwaytofindplayering[.]pro scam on Mozilla Firefox (GIF):
Screenshot of the fake updater installation setup:
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
- What is therightwaytofindplayering.pro pop-up?
- How to identify a pop-up scam?
- How do pop-up scams work?
- How to remove fake pop-ups?
- How to prevent fake pop-ups?
- What to do if you fell for a pop-up scam?
How to identify a pop-up scam?
Pop-up windows with various fake messages are a common type of lures cybercriminals use. They collect sensitive personal data, trick Internet users into calling fake tech support numbers, subscribe to useless online services, invest in shady cryptocurrency schemes, etc.
While in the majority of cases these pop-ups don't infect users' devices with malware, they can cause direct monetary loss or could result in identity theft.
Cybercriminals strive to create their rogue pop-up windows to look trustworthy, however, scams typically have the following characteristics:
- Spelling mistakes and non-professional images - Closely inspect the information displayed in a pop-up. Spelling mistakes and unprofessional images could be a sign of a scam.
- Sense of urgency - Countdown timer with a couple of minutes on it, asking you to enter your personal information or subscribe to some online service.
- Statements that you won something - If you haven't participated in a lottery, online competition, etc., and you see a pop-up window stating that you won.
- Computer or mobile device scan - A pop-up window that scans your device and informs of detected issues - is undoubtedly a scam; webpages cannot perform such actions.
- Exclusivity - Pop-up windows stating that only you are given secret access to a financial scheme that can quickly make you rich.
Example of a pop-up scam:
How do pop-up scams work?
Cybercriminals and deceptive marketers usually use various advertising networks, search engine poisoning techniques, and shady websites to generate traffic to their pop-ups. Users land on their online lures after clicking on fake download buttons, using a torrent website, or simply clicking on an Internet search engine result.
Based on users' location and device information, they are presented with a scam pop-up. Lures presented in such pop-ups range from get-rich-quick schemes to fake virus scans.
How to remove fake pop-ups?
In most cases, pop-up scams do not infect users' devices with malware. If you encountered a scam pop-up, simply closing it should be enough. In some cases scam, pop-ups may be hard to close; in such cases - close your Internet browser and restart it.
In extremely rare cases, you might need to reset your Internet browser. For this, use our instructions explaining how to reset Internet browser settings.
How to prevent fake pop-ups?
To prevent seeing pop-up scams, you should visit only reputable websites. Torrent, Crack, free online movie streaming, YouTube video download, and other websites of similar reputation commonly redirect Internet users to pop-up scams.
To minimize the risk of encountering pop-up scams, you should keep your Internet browsers up-to-date and use reputable anti-malware application. For this purpose, we recommend Combo Cleaner Antivirus for Windows.
What to do if you fell for a pop-up scam?
This depends on the type of scam that you fell for. Most commonly, pop-up scams try to trick users into sending money, giving away personal information, or giving access to one's device.
- If you sent money to scammers: You should contact your financial institution and explain that you were scammed. If informed promptly, there's a chance to get your money back.
- If you gave away your personal information: You should change your passwords and enable two-factor authentication in all online services that you use. Visit Federal Trade Commission to report identity theft and get personalized recovery steps.
- If you let scammers connect to your device: You should scan your computer with reputable anti-malware (we recommend Combo Cleaner Antivirus for Windows) - cyber criminals could have planted trojans, keyloggers, and other malware, don't use your computer until removing possible threats.
- Help other Internet users: report Internet scams to Federal Trade Commission.