Monday, April 14, 2014

Remove POSHCODER Ransomware that Encrypt My Documents


In the wake of CryptoDefense and Bit, here comes another encrypting ransomware known as POSHCODER. They all work based on the same mechanism. Once POSHCODER affects a machine, all the documents would refuse to open; instead lines of threatening words will be displayed to ask for Bitcoin as ransom.



How POSHCODER Ransomware Penetrates A Machine


As computer becomes one of the most required items in nowadays life and Internet becomes the most powerful thing to connect the whole world, cyber criminals are prone to embed vicious codes on the Internet for rapid propagation and wider penetration. POSHCODER ransomware is actually geared by Trojan horse, the one is adept at exploiting backdoor/vulnerability/bugs/loopholes. Thus all the actions resulting in any one of these things would give the encrypting ransomware fact chance for infiltration:
  1. Access some prohibited sites, porn sites especially.
  2. Download and install the programs bundled with browser hijacker or sticky extensions.
  3. No regular check on computer health by running full scan for any possible virus and vulnerability.


POSHCODER Ransomware Truth

Sunday, April 13, 2014

Remove Trojan horse Downloader.Generic13 that Brings in Additional Virus

Trojan horse Downloader.Generic13 is a collective name. As its name suggests, it is created to help download additional infections, Trojan horse particularly. Recently, survey data shows that such downloader Trojan has been utilized by other types of malware, PUP and infections to alleviate affection and infiltration.



Trojan horse Downloader.Generic13 Payloads

  1. Numerate drivers concerning security service and background processes to disabled automatic removal and call service on its undertaking.
  2. Modify DNS settings and utilize seldom use ports to access designated site for virus downloading.
  3. Open up backdoor invisible to PC victims to be exploited by cooperators.



Trojan horse Downloader.Generic13 Damages


With random modification and more injection of unknown items, the below issues would be incurred:

Remove Trojan Horse Generic35 that Causes Corrupted Executable file and Disabled WLM

Infected with Trojan horse Generic35
  • COM surrogates keep using all your CPU.
  • Additional pop-up ads are showing on a computer. 
  • Trojan horse Generic35 keeps calling C:\Windows\explorer.exe.
  • Browser hijacking and redirecting problem start showing up.
  • Unsolicited installations are made.
  • Error messages would be triggered.


Who Sent Trojan Horse Generic35 to My Computer?


Saturday, April 12, 2014

Stop Linkbucks.com Pop-up Ads for Perfect Surfing

What Is Linkbucks.com?


As its name suggests, it is an original linkbucks site that could generate profit if one share one web site through the platform and gain clicks (this is what we call PPC). It is said that linkbucks was established in 2005 and has obtained great development until it gave PC users with pop-up ads. When one is exchanging link, one will be bombarded with some adult content. Other ads coming together with linkbucks.com are:
  • AdF.ly
  • Adfoc.us


Linkbucks.com Is Not Recommended


As more such advertising platform mushrooming nowadays, it needs more fun to sustain operation and needs more cooperators for promotion. Thus more ads are brought in by linkbucks.com. Given the fact that linkbucks.com would publish adult content, it can be inferred that it does no filtering work when choosing cooperators. Spam sites and some loosely programmed sites can gain access through the advertising platform. In such case, the computer harassed by linkbucks pop-up ads will become likely to be affected by unknown infections as bugs can be easily detected and exploited.

Remove Webcake by Conduit: WebCake Ads, Adware:Win32/WebCake and WebCake.BHO

Webcake Affection Scenario Outline


Webcake is one of the products issued by Conduit. It comes in forms of adware, extension and browser hijacker. Supported by adware:Win32/WebCake is not necessarily indicating that webcake is totally an adware, in fact, it can also be browser hijacker that intercept traffic with some rogue means for its operators. Affected by Webcake, victims would encounter mess on browsers:
  1. Countless pop-up ads to cover some content on web sites.
  2. Random browser jacking and redirecting.
  3. Slow speed in displaying web pages.
  4. Browser freezes and occasional crash.
  5. Low internal storage is the most prominent symptom along with the browser mess.


Webcake Is Not Virus But Potentially Dangerous


Herein, we do not use the word virus to describe webcake, this is the answer to the question by some victims that “why Google allow webcake to hijack browser”. It is no more than a traffic exchanging site. To put it plain, operators use webcake to hijack traffic so as to raise the ranking in search engine.