Faking It

Newsfeed

Nachrichtenbote
Got a copy of the 'Homeview Installer' today which looked harmless enough...

During installation, it runs the user through a series of procedures that look pretty routine.

agent_fln_install_1.jpg


If I try to cancel the installation at the first screen, it is nice enough to ask me if I really want to continue...

agent_fln_install_quit.jpg


And if I change my mind and install it anyway...

agent_fln_install_2.jpg


agent_fln_install_4.jpg


agent_fln_install_3.jpg


But when installation is "completed successfully", it turns out Homeview isn't really installed.

agent_fln_no_homeview.jpg


There's just an uninstaller file that, true enough, really does remove the Homeview folder from the Program Files, and the Homeview-related registry entries.

So it really just came and went without doing anything... Oh wait, it installed Trojan:W32/DNSChanger.ARNF and none of my clicks even mattered.

Crafty little thing.

Just a reminder - do be wary of executing any file you download or receive via e-mail, if you are unsure of its trustworthiness.


Response team post by - Christine On 11/12/08 At 05:20 AM



Weiterlesen...
 
Zurück
Oben