Are all Adware products “Spyware”?

No, but the majority are. There are also products that do display advertising but do not install any tracking mechanism on your system. These products are not indexed in our database.
Free Anti Spywares

Information and Removal »

Phishing Pages Pose as Secure Login Pages
[8 Feb 2010 | No Comment | ]

TrendLabs recently spotted a new phishing site spoofing CenturyLink’s secure login page from one of its anti-phishing resources.

Click for larger view Click for larger view

CenturyLink, created by the merger of CenturyTel and Embarq on July 1, 2009, is a leading provider of high-quality voice, broadband, and video services through its advanced communication networks to consumers and businesses in 33 states in the United States. It is the currently the fourth largest local exchange telephone company in the United States in terms of access lines. It has more than 7 million access lines in service and more than 2 million high-speed Internet connections as well as its own 100 percent digital network, Centrex, ISDN, and advanced intelligent network.

Even though CyberLink’s real secure login page looks very similar to the spoofed one, there are still at least three major differences. First, the URL of the real login page is https://secure.centurylink.net/login.php begins with one of the first marks of a secure login page (https), followed by the company name, unlike the spoofed one, http://www.{BLOCKED}gsoo.com/g4/data/file/news/CenturyLink.net.html, which begins with http, followed by a suspicious-looking domain name before the company’s own name.

Next, a secure login page always has a padlock icon on the lower-right portion of the page while the fake page only has an exclamation point, indicating that something is wrong.

Finally, look at the lower-left portion of the spoofed page, though it is marked as “Done,” it clearly contains errors, as evidenced again by the exclamation point.

Users who unknowingly end up in the malicious site and enter their credentials are at risk of losing critical personal credentials or maybe even their identities, as clicking the Log In button sends the user data to the cybercriminals behind this attack. As of this writing, however, the phishing page is no longer active.

There are several ways by which you can tell if you are being phished, the three techniques mentioned above are just some of the more noticeable ones, particularly in this attack. But there are also several ways by which users can protect themselves from being phished. Awareness, in this regard, is clearly key.

Trend Micro™ Smart Protection Network™ protects users from this kind of attack by blocking user access to malicious sites and domains.

Post from: TrendLabs | Malware Blog - by Trend Micro

Phishing Pages Pose as Secure Login Pages

Information and Removal »

Caisse d’Epargne Customers, Beware!
[8 Feb 2010 | No Comment | ]

It seems that cybercriminals will really stop at nothing to further their malicious activities. Trend Micro fraud analysts received yet another spammed message obviously designed to catch unwitting Caisse d’Epargne, a French semicooperative bank, customers into their phishing trap.

Founded in 1818, with around 4,700 branches in France, Caisse d’Epargne is active in both the retail and private banking segments. It also holds a significant stake in the publicly traded investment bank, Natixis.

The spammed message informs customers that the bank found some problems with their accounts. It then informs the recipients that the bank needs them to fill in additional information by clicking an embedded link in the email to keep them protected. Clicking the link, however,  redirects users to a phishing page that looks a lot like the bank’s official website.

Click for larger view

As expected, the phishing site asks users to enter their personal identification numbers (PINs) to validate their accounts. There are, however, noticeable differences between the phishing site (marked in red in Figure 2) and the bank’s legitimate site (marked in green in Figure 3) if only users take time out to make sure they are not being victimized by wily cybercriminals.

Click for larger view Click for larger view

In fact, the bank’s legitimate site even has a security warning (marked in green in Figure 4) to all of its customers regarding the said phishing attack since January 28.

Click for larger view

The continued proliferation of phishing attacks, as evidenced by this, supports the “2009 Third Quarter Report” released by the Anti-Phishing Working Group (APWG). Based on the group’s global phishing survey, the third quarter of 2009 broke the record with 40,621 unique phishing reports as of August.

However, what is more often overlooked can be summarized by the question, “What really happens after a phishing attack?” Trend Micro partner, RSA Security, gave some really frightening answers to this question. The article describes a real-life scenario that shows how cybercriminals buy credit card information, which they use to purchase high-end merchandise online. Fraudsters then resell these products, enabling them to make substantial profits.

Considering the persistence with which cybercriminals operate, users should thus be extremely cautious every time they conduct online transactions. Fortunately, Trend Micro™ Smart Protection Network™ already protects product users from this particular threat by preventing the spammed message from even reaching their inboxes and by blocking user access to the phishing site.

Non-Trend Micro product users can also stay protected from malicious URLs by using one of Trend Micro’s free tools, Web Protection Add-On.

Post from: TrendLabs | Malware Blog - by Trend Micro

Caisse d’Epargne Customers, Beware!

Information and Removal »

Agnitum delivers Outpost 6.7.3 with new auto-update functions
[8 Feb 2010 | No Comment | ]

Good news, everyone! :-)

Today we shipped another iteration of Outpost 6.7 solutions - 6.7.3.

With this release Agnitum introduces daily updates of Outpost installation packages. What we mean is regular incorporation of new malware and rule databases into Outpost. During the workday, these bases come embedded into the installation package and downloadable from the web-site.

It is the result of new internal automation processes in Agnitum’s R&D implemented since 6.7.2 edition.

This tweak brings great savings for customers who won’t have to waste time and Internet traffic to constantly download updated bases. A good advantage over competitors who tend to bloat their installation packages up to 150% of the original volume just for that reason.

To sum up, the improvements ensure:

  • increased frequency of malware database updates: updates are now delivered three times a day (minimum) on weekdays
  • Anti-Malware engine now gets auto-updated through regular malware database updates, meaning that for receiving new features and fixes no separate product update is needed

You may find Outpost 6.7.3 solutions at http://www.agnitum.com/products/.

Information and Removal »

Paladin Antivirus
[8 Feb 2010 | No Comment | ]

Paladin Antivirus is a rogue anti-spyware, fake security application which must be avoided in any circumstances. That should be not a surprise because Paladin Antivirus was created by the same hackers who are to blame for releasing Malware Defense, another dangerous program posing to be legitimate.
Paladin Antivirus uses the same means of distribution where Trojans [...]

Information and Removal »

Farmeset.com Hijacker
[5 Feb 2010 | No Comment | ]

Stay clear of Farmeset.com domain if you don’t want to get your computer infected. This domain is related to SafePcAv (or Safe PC AV) application which is known as rogue anti-spyware tool. Take a look at the screen shot below to recognize this infections.
The site reminds of My Computer window and even correctly reflects your [...]