Lavasoft Blog http://www.lavasoft.com/mylavasoft/company/blog en Malware Arrests Send Message to Cyber Thieves http://www.lavasoft.com/mylavasoft/company/blog/malware-arrests-send-message-to-cyber-thieves <p>This past week, news broke that British police have made groundbreaking headway in combating cyber crime, making the first arrests in Europe of two people suspected of distributing Zeus – a sophisticated Trojan designed to steal sensitive data. On November 3, the <a href="http://cms.met.police.uk/news/arrests_and_charges/trojan_computer_virus_arrests" target="_blank">Metropolitan Police’s Central e-Crime Unit</a> arrested a man and a woman in Manchester, England on suspicion of helping spread the Trojan, known as Zeus or Zbot.</p> <p>At Lavasoft, we detect this threat as ‘Win32.TrojanSpy.Zbot’ in <a href="http://www.lavasoft.com/products/ad_aware.php" target="_self">Ad-Aware's</a> Detection Database; it’s a type of malicious program that can steal information such as passwords, surfing habits, credit card details and e-mail addresses. According to a <a href="http://cms.met.police.uk/news/arrests_and_charges/trojan_computer_virus_arrests" target="_blank">statement on its website</a>, the Metropolitan Police say that the malware allowed distributors to harvest “millions of lines of data from affected machines – hundreds of thousands per day…”</p> <p>What does this breakthrough mean for combating malware? Andy Browne, the team leader of the <a href="http://www.lavasoft.com/mylavasoft/securitycenter/blog" target="_self">Malware Labs</a> here at Lavasoft, says that the arrests of two suspects distributing Zbot sends a long overdue and strong message that such behavior is a serious criminal offense and will not tolerated. Good work, Scotland Yard!</p> http://www.lavasoft.com/mylavasoft/company/blog/malware-arrests-send-message-to-cyber-thieves#comments company Industry and Security News Fri, 20 Nov 2009 17:11:25 +0000 Erin 6032 at http://www.lavasoft.com/mylavasoft Law Firms and PR Groups Targeted in Spear Phishing Attacks http://www.lavasoft.com/mylavasoft/company/blog/law-firms-and-pr-groups-targeted-in-spear-phishing-attacks <p>The U.S. Federal Bureau of Investigation has issued a new advisory for law firms and PR companies to take heed of:</p> <p>By way of an ongoing FBI investigation, it’s been found that hackers are increasingly targeting U.S. law firms and public relations groups with spear phishing e-mails containing malicious payloads, in an attempt to break into their computer networks to steal sensitive information.</p> <p>According to the <a href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">FBI’s e-scam advisory</a>:</p> <p style=" 30px;"><em>“Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link. Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests.”</em></p> <p>For full details, read the <a href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">FBI's warning</a> or <a href="http://www.nytimes.com/aponline/2009/11/17/business/AP-US-Hacking-Firms.html" target="_blank"><em>The New York Times</em>’ recent coverage</a> on this.</p> http://www.lavasoft.com/mylavasoft/company/blog/law-firms-and-pr-groups-targeted-in-spear-phishing-attacks#comments company Industry and Security News Security Alerts Wed, 18 Nov 2009 15:49:54 +0000 Erin 5891 at http://www.lavasoft.com/mylavasoft What's New in Ad-Aware? http://www.lavasoft.com/mylavasoft/company/blog/whats-new-in-adaware <p>You may have seen our blog post last week giving you <a href="http://www.lavasoft.com/mylavasoft/support/blog/adaware-game-edition-quick-look" target="_self">a look at the new Ad-Aware Game Edition</a>, the spin-off of Ad-Aware that provides protection to gamers as they play.</p><p>Did you know that we also have a video tutorial available on the latest version of Ad-Aware? Have a look below to get a good, brief overview of <a href="http://www.lavasoft.com/products/ad_aware.php" target="_self">Ad-Aware Internet Security</a>.</p><p>&nbsp;</p><p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/AxFztEdq8fE&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=sv&amp;feature=player_embedded&amp;fs=1"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><embed type="application/x-shockwave-flash" src="http://www.youtube.com/v/AxFztEdq8fE&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=sv&amp;feature=player_embedded&amp;fs=1" allowfullscreen="true" allowscriptaccess="always" width="425" height="344"></object></p><p>Those of you who have been enjoying the new version for the past several weeks may already be familiar with what's being discussed in this one, but please take a peek and pass it on to anyone you know interested in learning more about the latest Ad-Aware and getting a guided tour through the new features.</p> http://www.lavasoft.com/mylavasoft/company/blog/whats-new-in-adaware#comments company Lavasoft Products Mon, 16 Nov 2009 21:47:16 +0000 Erin 5888 at http://www.lavasoft.com/mylavasoft Ad-Aware Game Edition - Quick Look.... http://www.lavasoft.com/mylavasoft/support/blog/adaware-game-edition-quick-look <object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/kCjwLMYvSxM&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><embed type="application/x-shockwave-flash" src="http://www.youtube.com/v/kCjwLMYvSxM&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en&amp;feature=player_embedded&amp;fs=1" allowfullscreen="true" allowscriptaccess="always" width="425" height="344"></object> http://www.lavasoft.com/mylavasoft/support/blog/adaware-game-edition-quick-look#comments company Support How to Lavasoft Products Thu, 12 Nov 2009 07:47:38 +0000 LS Patrick 5768 at http://www.lavasoft.com/mylavasoft CamFrog Scam http://www.lavasoft.com/mylavasoft/securitycenter/blog/camfrog-scam <p>One of the most popular applications for cam sessions (<a href="http://en.wikipedia.org/wiki/Camfrog" target="_blank">CamFrog</a>) is now being abused for distribution of malicious software. The site, below, will appear if the victim visits camsjungle.XXX. The domain is more or less a <a href="http://en.wikipedia.org/wiki/Clone_%28computing%29" target="_blank">clone</a> of the real site, camfrog.com</p> <p style=" center;"><span class="inline inline-none"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/FakeCamFrog.png" alt="" title="" class="image image-_original " width="500" height="384" /></span></p> <p style=" center;">The cyber criminals have planted a fake version of CamFrog (<strong>CamFrogSetup.exe</strong>) on the server. The application looks like this:</p> <p style=" center;"><span class="inline inline-center"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/CamFrogScam2.png" alt="" title="" class="image image-_original " width="334" height="324" /></span></p> <p style=" left;">When the victim executes the fake application, a new malicious file will be downloaded.&nbsp; The file is a <span style="color: rgb(0, 0, 0);"><strong>Win32.TrojanDowloader.VB</strong></span> and will run in the background without the user's consent, connecting to suspicious servers. Ad-Aware’s <span style="color: rgb(0, 0, 0);"><strong>Genotype</strong></span> scanner will detect the malicious file as<span style="color: rgb(0, 0, 0);"> <strong>Win32.TrojanDowloader.VB/S</strong></span>.</p> <p style=" left;">Albin</p> <p style=" left;">Lavasoft Malware Labs</p> <p style=" left;">&nbsp;</p> <div class="image-clear"></div> http://www.lavasoft.com/mylavasoft/securitycenter/blog/camfrog-scam#comments company securitycenter Security Alert Wed, 11 Nov 2009 06:43:12 +0000 Albin 5766 at http://www.lavasoft.com/mylavasoft Vote Now in the 2009 Softonic Awards http://www.lavasoft.com/mylavasoft/support/blog/vote-now-in-the-2009-softonic-awards <p><a title="Softonic Awards 2009 - Finalist" href="http://en.softonic.com/awards2009"><span class="inline inline-left"></span></a><span style="font-size: 8.5pt; font-family: &quot;Courier New&quot;;"></span><span class="inline inline-left"><a href="http://en.softonic.com/awards2009"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/finalist_badge.png" alt="" title="" class="image image-_original " width="210" height="120" /></a></span>A new edition of the <a href="http://en.softonic.com/awards2009" target="_blank">Softonic Awards</a> is underway, and that means the race is on to see which software viewers pick as the best in 2009 across different categories and platforms. Please help us out by <a href="http://en.softonic.com/awards2009" target="_blank">voting for Ad-Aware</a> in the “<strong>Best Anti-Spyware</strong>” category, where we’re proud to say that we’ve been shortlisted again this year.</p> <p>Be sure to cast your vote soon to let your voice be heard and enter for your chance to win big – according to Softonic, everyone who participates in this year’s awards will be <a href="http://en.softonic.com/awards2009-prize" target="_blank">entered into a draw</a> to win a SEAT Ibiza, or €8,000. But keep in mind, the polls (available in <a href="http://en.softonic.com/awards2009" target="_blank">English</a>, <a href="http://www.softonic.com/awards2009" target="_blank">Spanish</a>, <a href="http://www.softonic.de/awards2009" target="_blank">German</a>, <a href="http://www.softonic.fr/awards2009" target="_blank">French</a>, <a href="http://www.softonic.it/awards2009" target="_blank">Italian</a> and <a href="http://www.softonic.com.br/awards2009" target="_blank">Portuguese</a>) are only open until November 30, 2009.</p> <p>And, we’d also like to thank all those who voted in these awards last year, giving Ad-Aware the win for “Best Anti-Spyware Program” in 2008. Let’s make it happen again this year!</p> <div class="image-clear"></div> http://www.lavasoft.com/mylavasoft/support/blog/vote-now-in-the-2009-softonic-awards#comments company securitycenter Support News about Lavasoft Tue, 10 Nov 2009 19:12:46 +0000 Erin 5762 at http://www.lavasoft.com/mylavasoft Quote of the Day http://www.lavasoft.com/mylavasoft/company/blog/quote-of-the-day <p><P>We recently came across an article that&nbsp;featured an interesting quote&nbsp;from one of our competitors, so I thought I would share it:</P><br /> <P><EM>“We’re the Toyota. A high quality brand - you get a great car for a reasonable price.” Acknowledging that the new products had been value priced Powledge said that they were targeted at people “Who don’t want to pay the highest prices, but want a quality solution.”</EM> <BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Tom Powledge, General Manager, PC Tools</P><br /> <P>Would that make us the Volvo..?</P><br /> <P>&nbsp;</P><br /> <P>&nbsp;</P><br /> <P>&nbsp;</P></p> http://www.lavasoft.com/mylavasoft/company/blog/quote-of-the-day#comments company Comment Tue, 10 Nov 2009 13:26:16 +0000 Lina 5753 at http://www.lavasoft.com/mylavasoft Framed by Malware http://www.lavasoft.com/mylavasoft/company/blog/framed-by-malware <p>It’s a disturbing occurrence that you don’t automatically think of in terms of the repercussions of a malware infestation…And according to <a href="http://www.nytimes.com/aponline/2009/11/08/business/AP-US-TEC-A-Virus-Framed-Me.html?_r=1" target="_blank">this recent Associated Press article</a>, it’s happening more often than you might imagine – innocent computer users unwittingly have pornographic images deposited on their PCs due to a virus, branding them as child abusers.</p> <p>Here’s an excerpt from <a href="http://www.nytimes.com/aponline/2009/11/08/business/AP-US-TEC-A-Virus-Framed-Me.html?_r=1" target="_blank">the article</a>:</p> <p style=" 30px;"><em>“Pedophiles can exploit virus-infected PCs to remotely store and view their stash without fear they'll get caught. Pranksters or someone trying to frame you can tap viruses to make it appear that you surf illegal Web sites. Whatever the motivation, you get child porn on your computer -- and might not realize it until police knock at your door.”</em></p> <p>The article goes on to detail an Associated Press investigation that found cases where innocent people have been accused as pedophiles when family or co-workers uncover images of child pornography on their PC, ultimately bringing devastating effects on the victims’ family, career, reputation and finances - in order to prove their innocence. Complicating many of these situations, the report explains, is the fact that pedophiles frequently blame viruses to explain the presence of pornographic images found on their PCs, making law enforcement skeptical of this defense.</p> <p>These types of cases are reminiscent of the plight of Connecticut, USA teacher <a href="http://en.wikipedia.org/wiki/Julie_Amero" target="_blank">Julie Amero</a>, the so-called "Spyware Teacher" who was facing up to 40 years behind bars after being convicted of exposing her students to pornography by allegedly accessing pornographic images on a classroom computer in October 2004. Amero's defense contended that the teacher had no control over the incident because malware on her computer caused a loop of pornographic pop-ups to barrage her screen. The controversial guilty verdict was then <a href="http://www.pcworld.com/article/132629/guilty_verdict_dropped_in_porn_popup_case_against_teacher.html" target="_blank">dropped in 2007</a>.</p> <p>&nbsp;</p> http://www.lavasoft.com/mylavasoft/company/blog/framed-by-malware#comments company Industry and Security News Mon, 09 Nov 2009 17:58:24 +0000 Erin 5748 at http://www.lavasoft.com/mylavasoft New Trojan Redirects to a Fake Media Codec Site http://www.lavasoft.com/mylavasoft/securitycenter/blog/new-trojan-redirects-to-a-fake-media-codec-site <p>There's a new Trojan out there that will cause annoying pop-ups and change the desktop background to entice victims to purchase their services.&nbsp; The new desktop background will appear like this:</p> <p><span class="inline inline-center"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/warningwincodec.png" alt="" title="" class="image image-_original " width="500" height="232" /></span></p> <p>If you choose to go further and click on the 'update now' button, you'll be redirected to a purchase page. This page gives a serious impression at first sight and the makers behind the site claim that:</p> <p><em>“WinCodecPro is not just a set of codecs to improve the audio and video quality on your computer! This newest development of SPACE Technology, thanks to it we were able to improve video image by 68%,to improve sound effects by 32% and to improve the quality of Flash by 46%!For the last 8 years products of SPACE Technology have proved their strong unsurpassed quality! WinCodecPro”</em></p> <p>The sad truth is that victims will be tricked into purchasing a trial package for $49.99 or the full package for $79.99. <em><br></em></p> <p><span class="inline inline-center"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/wincodecnet.jpg" alt="" title="" class="image image-_original " width="500" height="362" /></span></p> <p>This domain is fraudulent and plays on people’s lack of knowledge about media codecs. It’s recommended to always make some basic Google searches to verify how trustworthy the source is, to avoid scams like this.<br><br>Albin <br><br>Lavasoft Malware Labs</p> <div class="image-clear"></div> http://www.lavasoft.com/mylavasoft/securitycenter/blog/new-trojan-redirects-to-a-fake-media-codec-site#comments company securitycenter Security Alert Fri, 06 Nov 2009 13:24:33 +0000 Albin 5731 at http://www.lavasoft.com/mylavasoft Don’t Be a Billy http://www.lavasoft.com/mylavasoft/company/blog/don%E2%80%99t-be-a-billy <p>The <a href="http://www.staysafeonline.org/" target="_blank">National Cyber Security Alliance</a>, in its continued effort to promote online safety, has released a new web video, directed by filmmaker <a href="http://www.wagnervision.com/" target="_blank">Brett Wagner</a>.</p><p>This throwback to 1940’s classroom etiquette shows you what NOT to do online. Take a look at <em>'Don't Be A Billy'</em>:</p> <object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/nPR131wMKEo&hl=en&fs=1&"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/nPR131wMKEo&hl=en&fs=1&" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object> http://www.lavasoft.com/mylavasoft/company/blog/don%E2%80%99t-be-a-billy#comments company Security Tips Thu, 05 Nov 2009 15:39:20 +0000 Erin 5727 at http://www.lavasoft.com/mylavasoft New Rogue: BlockProtector http://www.lavasoft.com/mylavasoft/securitycenter/blog/new-rogue-blockprotector <p>The makers behind the<span style="color: rgb(255, 0, 0);"> <strong>Winiguard family</strong></span> never give up. They almost release a new clone application on a daily basis, and this time the rogue is named <span style="color: rgb(255, 0, 0);"><strong>BlockProtector</strong></span>.</p> <p><span class="inline inline-center"><img src="http://www.lavasoft.com/mylavasoft/sites/default/files/images/BlockProtector.jpg" alt="" title="" class="image image-_original " width="500" height="370" /></span></p> <p>Albin</p> <p>Lavasoft Malware Labs</p> <p>&nbsp;</p> <div class="image-clear"></div> http://www.lavasoft.com/mylavasoft/securitycenter/blog/new-rogue-blockprotector#comments company securitycenter Security Alert Thu, 05 Nov 2009 08:28:40 +0000 Albin 5724 at http://www.lavasoft.com/mylavasoft IT Blog Awards 2009 - Vote Lavasoft! http://www.lavasoft.com/mylavasoft/securitycenter/blog/it-blog-awards-2009-vote-lavasoft <p>Computer Weekly is now running its second annual IT Blog Awards 2009 contest. The Lavasoft blog has been nominated this year in the “IT Security” category.</p> <p>We need your help - if we’re among your favorite security blogs, please take a moment to help us out by casting a vote for Lavasoft! <a href="http://www.computerweekly.com/Articles/2009/11/03/238190/vote-in-the-computer-weekly-it-blog-awards-2009.htm" target="_blank">Details here</a>.</p> <p>&nbsp;</p> http://www.lavasoft.com/mylavasoft/securitycenter/blog/it-blog-awards-2009-vote-lavasoft#comments company securitycenter News about Lavasoft Tue, 03 Nov 2009 17:01:03 +0000 Erin 5484 at http://www.lavasoft.com/mylavasoft