Articles Archive for 19 November 2008

Delf Trojan threat: information and removal
Posted in Information and Removal on 19 November 2008

Delf trojan causes lots of troubles because of its destructive payload. Delf may crash the system and make it inoperative. It may also slow down computer’s performance. Delf Trojan grants a remote attacker access to the compromised machine. It also allows the attacker to control the computer. Delf should be removed as soon as possible; …

possible downsides to morro
Posted in Information and Removal on 19 November 2008

if you haven’t heard the news microsoft is killing onecare and replacing it with a free anti-malware tool probably using the same engine as the current product…i’ve written about microsoft’s entry into the anti-malware space before and i wasn’t very …

Trojan-Downloader.Win32.Dadobra.bru threat: information and removal
Posted in Information and Removal on 19 November 2008

Trojan-Downloader.Win32.Dadobra.bru is also known simply as Dadobra trojan. This infection is not very dangerous on its own, but it downloads corrupt security tools and those are both annoying and troubling. Dadobra is also responsible for slowing system performance and making a computer halt. Trojan-Downloader.Win32.Dadobra sets itself to run on boot by modifying Windows registry.

You should …

StartPage.c threat: information and removal
Posted in Information and Removal on 19 November 2008

The purpose of StartPage.c trojan is hijacking web browser. Just like its previous versions (StartPage ir StartPage.b) StartPage.c redirects web browser to certain website. According to the latest reports, StartPage.c  opens okww.net instead of what user types into address bar.

The okww.net is fraudulent and capable of installing other malwares without visitor’s consent. Unfortunately, people can’t …

ManageDNS404.com threat: information and removal
Posted in Information and Removal on 19 November 2008

ManageDNS404 browser hijacker is a dangerous one. It sticks on a computer after people visit managedns404.com; they are usually redirected to that malicious website by trojan.

ManageDNS404.com website installs browser hijacker which prevents people from visiting other websites. Managedns404.com is fraudulent website. It looks like default “404” (“The page cannot be displayed”) error page, but that’s …

Check-AntiVir-Tool.net threat: information and removal
Posted in Information and Removal on 19 November 2008

Check-AntiVir-Tool.net is yet another browser hijacker designed to promote WinSpywareProtect fraud. It is a clone of Av-antivir-scanner-3.net, Av-check-online-scan.com and AVG-Online-Scanner.com hijackers.

Check-AntiVir-Tool.net redirects web browser to check-antivir-tool.net website that appears to be online virus scanner. The website imitates computer scan and reports various infections: New.NetDomain.Plugin Spyware, QQPass I Password Capture, Matcash BG Trojan high, SillyDI Spyware …

FunWebProducts threat: information and removal
Posted in Information and Removal on 19 November 2008

FunWebProducts is a set of free to use programs promoted on various websites and distributed on funwebproducts.com. Software offered by Fun Web Products may look appealing: they distribute free screensavers, free mouse cursors, the infamous Zwinky virtual dolls, free emoticons for email and many other things like that.

The services might seem to be useful, but …

PayPal Spam Warns of Fraud, Installs Worm Instead
Posted in Information and Removal on 19 November 2008

A new fake PayPal email message is being spammed — this time, it is not the typical PayPal phishing email that everyone is accustomed to. Instead of including links asking for the recipient’s personal information, this spammed message asks users to open a .ZIP attachment.
Here’s a sample email:

Figure 1. This supposed PayPal email message warns [...]

Phishers Take Aim at Slingshot
Posted in Information and Removal on 19 November 2008

The Trend Micro Content Security Team just discovered a phishing attack targeting Slingshot Communications, Inc. A phishing email pretends to update a customer’s existing account. It also includes the legitimate contact number of the company to make it seem authentic.
Figure 1. Phishing email sent to users

Figure 2. The Slingshot phishing site

Slingshot Communications, Inc. is the [...]

Email.Phishing.Bank-94
Posted in ClamAV on 19 November 2008