Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Wednesday, 2 March 2011

New rogue anti spyware - AlfaCleaner [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

Sunbelt and Spyware Warrior reports about new rogue anti spyware AlfaCleaner.
alfa cleaner rogue antispyware
AlfaCleaner is a variant of the Anti Virus Pro, Winhound Spyware Remover, & XSRemover
Downloadable from alfacleaner.com, innovagest2000.com


We recommend to blocking specific domains and IP address:



x-stories.org – 69.50.187.19
zlex.org – 85.255.115.227, 85.255.116.213, 85.255.117.51
Noi.themovie.com that calls the x-stories.org – 69.50.187.19
Cleanchan.net – (formally fullchain.net) -195.255.177.21


If your PC don`t have WMF patch, please patch now. The Alfa Cleaner using wmf exploit for install.


Update: read How to remove AlfaCleaner

February 2, 2006 on 6:51 am | In Rogue Anti Spyware | 3 Comments |



RSS feed for comments on this post. TrackBack URI


My Anti Spyware - Free antispyware programs and Spyware Removal Instructions.


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Wednesday, 16 February 2011

Wimamp exploit used to push spyware [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

The Winamp vulnerability in version 5.12 was announced at Secunia just a few days ago, details here. Note the Secunia advisory says “an exploit is publicly available”. Nullsoft released Wimamp 5.13 the same day the exploit was announced, but the spyware pushers saw an opportunity to infect more machines and make more money. SunbeltBLOG posted a Winamp exploit found in the wild today. A malicious Winamp playlist file (.pls) was discovered that causes Winamp to open and subsequently download an ugly CoolWebSearch infection called HomeSearch Assistant, also dubbed Trojan/Startpage.HSA, along with ransomware anti-spyware SpySheriff. The Sunbelt post states the exploit takes place from 008k.com, IP 195.225.177.27 at Netcathosting and recommends network admins and home users to block the site. Netcathosting is one of those ISP’s known to host spyware. Sunbelt also posted a screenshot of the hijacked browser showing domain lookfor.cc (link to dnsstuff.com).

February 6, 2006 on 12:30 am | In Exploits & Vulnerabilities | No Comments |



RSS feed for comments on this post. TrackBack URI



My Anti Spyware - Free antispyware programs and Spyware Removal Instruction


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS