Archive | Malware Warnings RSS feed for this section

Searching Online Whitepages Often Leads To Rogue Antivirus…or Worse

I’m often curious on how my clients become infected.  What websites they visited, what they were searching for and of course what kind of protection they had on their computer.  whitepages_malware

After taking notes for a month it seams that 75% of the clients infected with rogue (fake) anti-virus first observed the rogues infecting their PC after searching for a persons phone number online.

So, reader beware.  I would suggest using whitepages.com if you need to find someones phone number.



Read full story · Comments { 4 }

Nasty New Rootkit Patches Atapi.sys

For the past 7 days I’ve been seeing a new rootkit (not sure of the name) that patches the atapi.sys driver.  This rootkit was NOT detected by any of the applications I use in my bootable anti-malware toolkit. Full scans with:

  • Avira
  • SAS
  • MBAM
  • Spyware Doctor
  • GMER

revealed nothing.  I was still getting all searches in any browser redirected to scam sites.  I usually don’t like running Combofix on Vista, but I had no choice.  Sure enough Combofix detected a rootkit and disinfected it!   Again, the rootkit infected the atapi.sys driver which redirected all searches and probably downloaded a few randomly named exe’s to the system32 directory.

combofix-rootkit

Read full story · Comments { 35 }

Remove-Malware Traffic Stats