Showing posts with label Browser Hijacking. Show all posts
Showing posts with label Browser Hijacking. Show all posts

Sunday, 8 November 2015

Rediscovered Adware That Replaces Full Browser


Warning for the second time in a short time researchers for browsers that have the display of advertisements as target and all installed browsers trying to replace. It involves two browsers called eFast and Cross Browser, which both are based on Chromium.

Chromium is an open source web browser developed by Google that is the basis for Google Chrome. Other parties can use Chromium as the basis for their browser, such as Comodo Dragon, Vivaldi, SRWare Iron and Opera. Also dubious parties seem now to deal with Chromium. Instead of infecting existing browsers with adware is chosen to develop its own browser that displays ads and replaces the existing browser. Once the browser is started and ads appear dubious domains are loaded.

Browse Cross is part of a notorious adware family called Cross Rider. Initially it went to "browser hijackers' and adware were only existing browsers hijacked. According to anti-malware company Malwarebytes does so still, but there is now also a fully functional browser appeared. Once active remove both cross Browse eFast as shortcuts to the default browser on the desktop, start menu and taskbar, and then add a shortcut to the native browser.

The rogue browsers via 'wrappers and bundled software distributed. A wrapper is an installer that besides a certain program can also install other software.

Wednesday, 1 July 2015

Hacked Routers Used To Distribute Malware Dyre



Cyber criminals hacked routers to distribute the Dyre-malware, as discovered and reported Bryan Campbell , security researcher at Fujitsu. Dyre , also known as Dyreza, is a Trojan specifically designed to steal money from online bank accounts.

Be emails with infected e-mail attachments used for the distribution of Dyre. Annexes instance pose as an invoice, but is actually the Upatre downloader that eventually install the Dyre Trojan on the computer. Once active Dyre will the browser (Internet Explorer, Google Chrome or Firefox) and hijack login information for online banking returned to the criminals. Then the malware installs a spam module on the computer and will use it to send new e-mails.

Campbell found that Dyre used to install the "payload" hacked routers. It is Ubiquiti Networks routers that use the operating system airos. Besides these routers would also routers manufacturer MicroTiK, running on RouterOS, are the target. The researcher makes on his own blog know that making the Dyre instances that he studied with many hacked airos routers connection. The routers are probably using known vulnerabilities or default credentials hijacked.

Saturday, 14 March 2015

Firefox Probably Get Automatic Repair Function


Mozilla is working on an experimental system that Firefox soon own problems in the browser can notice to remedy that then automatically and proactively. This relates for example to a hijacked or custom search engine that will restore the original state browser.

Possibly Firefox are recovering the impact of undesirable or unwanted add-ons automatically. The new measure is called "Self Heal" and was last week during a meeting called between Firefox Developers (from minute 6:00 ). The discussion prior to Self Heal was about the signing of Firefox add-ons, which should mitigate the inconvenience of malicious browser extensions.Through Self Heal could be extended further.

Meanwhile, Mozilla also announced the availability of a " Self-Repair server "is announced, which should ensure that found Firefox can repair problems yourself. However, further details are still missing, and whether and when the function will be implemented exactly. To counter the nuisance of malicious add-ons and malware Google added two years ago, a reset button to Chrome to which recovers all kinds of custom settings in original state.