Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Guard Pro

Published: January 13, 2010 Reading time: 1 min

Guard Pro is a rogue antispyware software, or a phony. Guard Pro uses fake system scans and warnings to frighten people into buying the software. Guard Pro will show system scan results that report numerous infections, which are all fake, and will not remove the supposed infections until the user buys the product. Do not fall for this, it is a complete scam, Guard Pro is the infection itself. Guard Pro will also show system warnings and alerts stating the PC is infected or under attack and prompts the user to buy the software. ...

Continue Reading

McAfee Labs’ January Spam Report

Published: January 13, 2010 Reading time: 1 min

Angelina Jolie and Barack Obama are the #1 celeb subjects of choice for spammers, according to McAfee January Spam Report. The report also reveals: • The top 25 men and women that were spammed • Chinese pharma spam isn’t going away – in fact, on Dec 14, spam levels skyrocketed with subject lines advertising discounts on Pfizer drugs • “Free-hosting” websites to provide spam URLs has become a major target for spammers ...

Continue Reading

Warning On Possible Android Mobile Trojans

Published: January 13, 2010 Reading time: 2 min

Google’s Android mobile operating system has been out for a while and is generating more and more interest. Now there has been some buzz about fraudulent applications being posted on the Android Market. See these postings: Both of these apps were written by an anonymous developer known as 09Droid. In fact, he had a whole collection of online banking applications for sale on the Market: ...

Continue Reading

OWA-Malware is still being sent

Published: January 13, 2010 Reading time: 1 min

The Internet Storm Center reports that malware which claims to be “new Outlook Web Access settings” is still being sent out by cyber criminals. We saw those malware emails in the middle of October already.

Continue Reading

InSysSecure

Published: January 13, 2010 Reading time: 1 min

InSysSecure is a rogue security program, designed to rip people off. InSysSecure uses false security warnings, alerts and system scans to frighten people into thinking their computer systems are infected, all the while InSysSecure is the actual infection. if your system is infected with above malware, you should remove it soon, Click Here to learn how to remove it.

Continue Reading

W32/Fame

Published: January 12, 2010 Reading time: 1 min

Unlike the first malware authors who wrote viruses seeking fame through destruction, their motivation has changed to financial gain. Nevertheless, there are still the ones out there who share the first authors’ intent. I was analysing a simple Trojan today and saw the following message: It is not uncommon for malware authors to leave messages in their code for Researchers to read. This one did bring a smile to my face, so he was rewarded by it being named BackDoor-EKD which is an increment of one from BackDoor-EKC 😉

Continue Reading

Open season on tax-payers

Published: January 12, 2010 Reading time: 2 min

As any reader of this blog knows, cybercriminals can steal your money not just by putting malware on your machine, but by phishing attacks too. Phishing attacks don’t just target online banking and e-payment systems, but almost any site which asks the user to input sensitive data. Sites run by national government agencies are a prime example as they often demand a wealth of personal information which goes far beyond a simple user name or account number + PIN. While filling in a tax return online might seem like a great way to save time and paper, it gives cybercriminals a great opportunity to scoop all your details at once – data which could then be used to steal your identity and/or commit further crimes in your name. ...

Continue Reading

SysProtector

Published: January 12, 2010 Reading time: 1 min

SysProtector and ApcDefender are two new rogue antispyware programs released in the past 48 hours. SysProtector and APCDefender are potentially very dangerous PC infections. These rogues use fake security alerts and warnings to trick people into thinking their PC is under attack, all the while they drop fake files on the system. These rogues will also prevent other programs from opening, hijack the web browsers and render the PC nearly useless. Below is a screenshot of a hijacked browser, showing fake threat warnings. ...

Continue Reading

PCProtectar

Published: January 6, 2010 Reading time: 1 min

PCProtectar is the latest rogue security software infecting PC’s across the interwebs. PCProtecter uses false security warnings and system scan results to trick people into buying the software. If your PC has been infected with PCProtectar, don’t fall for the scam. Do not buy this software, it is completely useless and an infection in itself. PCProtectar is a potentially dangerous infection that may cause programs to stop working, web browsers to not open, making it impossible to access the internet. PCProtectar should be removed from infected computer systems immediately. ...

Continue Reading

How to rescue files encrypted by Data Doctor 2010?

Published: January 6, 2010 Reading time: 1 min

We have a tool available to do just that. Click Here. How to use dd2010_decrypter.exe to do batch processing: Place the encrypted files in a directory (i.e. c:\encrypted_files\) Copy dd2010_decrypter.exe into another directory and FROM THAT DIRECTORY, run the following command: for %f in (“c:\encrypted_files\.”) do dd2010_decrypter.exe %f %f.decrypted All files in the encrypted_files folder will be processed and the new decrypted files will have the same name but their extension will be “.decrypted.” ...

Continue Reading