<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Investigative Data Mining</title>
	<atom:link href="http://www.idmfraud.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.idmfraud.com</link>
	<description>Fraud Detection</description>
	<lastBuildDate>Wed, 14 Mar 2012 23:37:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>&#8220;PRS for Music&#8221; scam (virus) &#8211; how to identify &amp; resolve it</title>
		<link>http://www.idmfraud.com/prs-for-music-scam-virus-how-to-identify-resolve-it</link>
		<comments>http://www.idmfraud.com/prs-for-music-scam-virus-how-to-identify-resolve-it#comments</comments>
		<pubDate>Wed, 14 Mar 2012 23:29:16 +0000</pubDate>
		<dc:creator>Peter.Szucs</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[PRS]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.idmfraud.com/?p=746</guid>
		<description><![CDATA[Recently, I have been called to see if I can help with a computer problem, which turned out to be the most genuine looking scam I have seen in a long time. In this particular case, someone was using Facebook to play music videos and suddenly a message appeared across the whole screen to say [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, I have been called to see if I can help with a computer problem, which turned out to be the most genuine looking scam I have seen in a long time. In this particular case, someone was using Facebook to play music videos and suddenly a message appeared across the whole screen to say that “Illegally downloaded music pieces (pirated) have been located on your computer” and that he has to pay £50 to avoid prosecution and imprisonment.  Please see the picture below:</p>
<p><img class="alignleft" style="float: left;" src="http://www.idmfraud.com/images/prs-scam-blog.jpg" alt="" width="442" height="330" /></p>
<p>We quite rightly suspected from the beginning that this is not a genuine “lockdown” of computer and this was confirmed by the Metropolitan Police when we spoke to them shortly afterwards. Performing Right Society (PRS for Music) are also aware of this scam and recently <a href="http://www.prsformusic.com/aboutus/press/latestpressreleases/Pages/Statementoncomputerlockingscam.aspx">issued a statement</a> in which they clarify that they would never charge end users for watching music videos online.</p>
<p><strong>How to prevent receiving this scam/virus?</strong></p>
<p>-          Use up-to-date antivirus software</p>
<p>-          Use software/hardware firewall</p>
<p><strong>What to do when this virus is in your PC?</strong></p>
<p>-          Never make a payment to “unlock” your PC</p>
<p>-          Follow these steps to remove it:</p>
<ol>
<li>Hard reboot your PC into “Safe Mode with Command Prompt”. The key(s) to access the Safe Mode menu depends on make of your PC but generally it could be F8 or F6. Some PCs, i.e. Toshiba tablet use combination of Alt+F1.</li>
<li>You will have to type in your account password – make sure you log in to an account with administrative privileges</li>
<li>Once the Command Prompt appears you have few seconds to type in “explorer” and hit Enter. If you fail to do it within 2-3 seconds, the virus will take over and will not let you type anymore</li>
<li>If you managed to bring up Windows Explorer you can now browse into C:\windows\system32\restore\rstrui.exe and press Enter</li>
<li>Follow the steps to restore your PC into an earlier time/day</li>
<li>That’s it, your PC should be back to normal after reboot.</li>
</ol>
<p>-          Finally, report the scam on the <a href="https://reportlite.actionfraud.police.uk/?AspxAutoDetectCookieSupport=1">ACTION FRAUD’s website</a></p>
<p>Please note that the above solution applies to WinXP. If you are using Win7 the rstrui.exe is located in C:\windows\system32\rstrui.exe.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.idmfraud.com/prs-for-music-scam-virus-how-to-identify-resolve-it/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New Year&#8217;s Resolution: Recovering &#8220;lost&#8221; money and reducing financial risks</title>
		<link>http://www.idmfraud.com/new-years-resolution-recovering-lost-money-and-reducing-financial-risks</link>
		<comments>http://www.idmfraud.com/new-years-resolution-recovering-lost-money-and-reducing-financial-risks#comments</comments>
		<pubDate>Wed, 18 Jan 2012 14:11:30 +0000</pubDate>
		<dc:creator>Richard.Kusnierz</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[accounts payable]]></category>
		<category><![CDATA[financial risk]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://46.20.119.54/~idmfraud/?p=1</guid>
		<description><![CDATA[At the start of a new year I&#8217;d like to offer a self-funding opportunity which is risk free, has no downside and will re-assure corporate stake holders that your organisation is proactive in reviewing controls and safeguarding corporate assets. This is a two stage approach and makes use of the combined experience of Transaction Analysts [...]]]></description>
			<content:encoded><![CDATA[<p>At the start of a new year I&#8217;d like to offer a self-funding opportunity which is risk free, has no downside and will re-assure corporate stake holders that your organisation is proactive in reviewing controls and safeguarding corporate assets. This is a two stage approach and makes use of the combined experience of Transaction Analysts Limited and Investigative Data Mining Limited.</p>
<p>Stage 1 would be to perform a historic cost recovery audit of the last 5 years payments to third party suppliers. This is 100% risk free and on a contingency fee basis. If we don&#8217;t find and recover any over-payments there is no fee. If we recover significant over-payments, it indicates that the control mechanisms within Accounts Payables are not operating effectively and could be exploited.</p>
<p>Stage 2, given the significant recoveries made in Stage 1, funds exist to pay for a more exhaustive data mining review to identify further exposures and the warning signs of active fraud. In the current economic climate, the level of reported fraud has increased by 100% since last year, and the reality is that most organisations discover fraud by accident.</p>
<p>This strategy and methodology is self-funding and requires no budget.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.idmfraud.com/new-years-resolution-recovering-lost-money-and-reducing-financial-risks/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

