Articles Archive for 5 November 2008

More Google Searches Resulting in Rogue AV
Posted in Information and Removal on 5 November 2008

Seems like fake AV programs are still everywhere! Just a couple of weeks ago, Halloween costume searchers were targeted by these nasty programs through SEO poisoning. Now I’ve just encountered 2 scenarios resulting to rogue AV downloads, also done through hijacking of Google search results:
In the first scenario, queries for the string refa+zeitaufnahmebogen on the [...]

US Elections: Notable Threats
Posted in Information and Removal on 5 November 2008

Barack Obama becomes the 44th US president after a national elections that featured several notable online threats. Picture taken from CNN.
Media buzz about frontrunners began the US Presidential elections. Then there were the nomination processes for the two primary parties, then the party conventions, the debates and campaigns, and then Barack Obama’s victory on the [...]

E-Card.exe threat: information and removal
Posted in Information and Removal on 5 November 2008

E-Card.exe is a trojan that allows remote attacker to spy an infected machine. Anyone with bad intentions can steal sensitive information or make use of online banking accounts by employing e-Card.exe trojan; and trojans are not installed by someone with good wishes.

E-Card.exe infection is difficult to notice because it works secretly in a background. Fortunately, …

Trojan-Spy:W32/ZBot.XF
Posted in F-Secure on 5 November 2008

Trojan-Spy:W32/ZBot.XF is a trojan-spy.

Trojan-spy applications attempt to steal online banking login-information and other sensitive data from the infected computer.

ZBot.XF also targets online poker and gaming sites.

Exedrop threat: information and removal
Posted in Information and Removal on 5 November 2008

Exedrop is a dangerous trojan because it is able to download and install other malwares. This may lead to badly infected system.

Exedrop gets on a computer through infected MS Word files. Once, such a file is executed, Exedrop starts infecting other files and downloading malwares. It modifies security settings in order to be able to …

Win32/FakeAV.JW
Posted in CA Security Advisor on 5 November 2008

 

AVProScan.com threat: information and removal
Posted in Information and Removal on 5 November 2008

AVProScan.com is a smart browser hijacker. It is similar to other malware of this type, but avproscan.com website uses misleading design to trick people.

AVProScan.com regularly redirects users to avproscan.com website. The source is designed to look like folder on Windows operating system. The title of avproscan.com is “My Computer”, therefore people might easily get confused …

Trojan.Spy.Banker-6277
Posted in ClamAV on 5 November 2008

Kaspersky AVP: Trojan-Banker.Win32.Banbra.emt

Trojan.LdPinch-4668
Posted in ClamAV on 5 November 2008

Bitdefender: Trojan.Dropper.LdPinch.AO

Email.Phishing.Bank-82
Posted in ClamAV on 5 November 2008