Articles in the Information and Removal Category

Bogus LinkedIn Profiles Harbor Malicious Content
Posted in Information and Removal on 6 January 2009

The LinkedIn professional networking site connects more than 30 million users from across many different industries. The advantages of maintaining a list of trusted business contacts for career planning purposes is not lost on LinkedIn’s users.
The fostering of business relationships is further enhanced by features such as LinkedIn Answers and access from mobile devices.
Advanced Threats Researcher [...]

So Is It Twitter or Facebook?
Posted in Information and Removal on 6 January 2009

Neither. Or both. It depends on whether you think it is authentic or fake.
Twitter users are facing yet another attack, this time a phishing threat. A spamming operation previously flooded users of the social networking and micro-blogging site with follower notifications which led to spammy and bogus profiles.
Cyber criminals are now exploiting Twitter’s Direct Messages [...]

PRO Antispyware 2009 threat: information and removal
Posted in Information and Removal on 5 January 2009

PRO Antispyware 2009 is a new rogue anti-spyware program, a fake spyware remover, which uses scare tactics to trick the user into purchasing it’s "licensed version". This parasite typically enters the system by using trojans, such as Zlob or Vundo, but can also be manually downloaded and installed.

Once inside and active, PRO Antispyware 2009 will …

‘Classmates Reunion’ Used as Malware Ploy
Posted in Information and Removal on 1 January 2009

Class reunion invitations (supposedly from classmates.com) are being seen in  spam recently — recipients of these messages are asked to click on a link found in the message to get the details of the “reunion” and also see a related video.
Looking at the IP origins of sample spam messages, it appears that these have been [...]

Total Protect 2009 threat: information and removal
Posted in Information and Removal on 1 January 2009

Total Protect 2009 is a rogue anti-spyware application, fake spyware remover. This rogue can be installed via trojans. They  use system security holes to gain access into user’s PC. Also TotalProtect 2009 can be installed manually  from website that promotes this parasite. If PC runs slowly and the internet connectivity is  limited, then there is …

the MD5/rogue certificate attack
Posted in Information and Removal on 31 December 2008

i’m not going to bother pointing to all the many good stories out there describing the details of how a valid ssl certificate was faked by mounting a 2nd preimage attack on the MD5 hash using a legitimately purchased certificate as the starting point…..

Top 8 in ‘08
Posted in Information and Removal on 31 December 2008

Year-end lists are quite popular at this time of the year — here’s our own top threats in 2008.
Most Prolific: Mass Compromises
Attacks were targeted to a specific group of users and were targeted at popular Web sites. Diverse Web sites — entertainment, political, online shopping, social networking — were all used to spread malware. Compromises [...]

Express Antivirus 2009 threat: information and removal
Posted in Information and Removal on 30 December 2008

Express Antivirus 2009 is a rogue anti-spyware program, a fake spyware remover, which uses trojans, such as Zlob or Vundo, to enter the system, but can also be manually downloaded and installed. This parasite will try to intimidate the user into buying it’s "licensed version".

Once inside and active, Express Antivirus 2009 will flood the user …

Spy Guard 2008 threat: information and removal
Posted in Information and Removal on 30 December 2008

Spy Guard 2008 is a new rogue anti-spyware program, a fake spyware remover, which uses trojans, such as Zlob or Vundo, to enter the system. This parasite will try to trick the user into purchasing it’s "licensed version" by intimidating him with fake threats.

Once inside and active, Spy Guard 2008 will falsely inform the user …