Targeting the Source: FAKEAV and Malicious Domains

In order to monetize their malicious activities, botnet operators, spammers, and those behind blackhat search engine optimization (SEO) campaigns create accounts with a network of FAKEAV affiliates. These affiliates supply URLs to landing pages that display false antivirus scanners and that attempt to scare users into installing rogue antivirus software. If users purchase the fake [...]

DLL-Based FAKEAV Returns, in the Wild Again

In our previous FAKEAV white paper, we presented how Trend Micro researchers tracked down the evolution of FAKEAV and followed its development behaviorwise from one generation to the next. One of the earlier generations (fourth, to be exact) in the paper comprises DLL-based FAKEAV—fake antivirus that use a .DLL file to perform all of their malicious routines to primarily [...]

Stalking TDL4: All Access Pass to the Hard Drive

Recently my colleagues and I have been analyzing TDL4 — a variant of the well known malware family TDSS. TDSS, as we know, is and advanced malware that evades detection by going back to where we stopped looking long ago: in the boot sector. Back in the 16-bit DOS days, boot viruses spread from [...]

Man-in-the-Browser attacks target the enterprise

With firewalls, antivirus and other security mechanisms protecting corporate networks, how do attackers manage to penetrate enterprise computer systems? Simply by exploiting the weakest link in the security chain. One of the newest methods is tunnelling in via employees’ browsers using an attack known as “Man-in-the-Browser” (MitB).

Read entire article

Anti-Virus Software Driving You Mad? 5 Fight-Back Tips

Last week some Windows users struggled through unexpected PC slowdowns due to a security program bundled in with a Java update. Security programs still hog PC resources and pose annoyances — but here’s expert advice on how you can regain control.

Read entire article