CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Trojan-Spy.HTML.Fraud.gen url spoofer and Paypal FYI

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
goldberry

Cadet
Cadet


Joined: Jul 06, 2004
Posts: 4
Location: USA

PostPosted: Thu Dec 23, 2004 4:24 pm    Post subject: Trojan-Spy.HTML.Fraud.gen url spoofer and Paypal FYI
Reply with quote

I use Paypal to accept payments for items I sell at eBay. Yesterday, as I was securely logged in to Paypal thru a link from eBay, I clicked on the link to bring me to my history view. Kaspersky antivirus popped up and told me that Trojan-Spy.HTML.Fraud.gen was stopped as my history page was loading. I'm not saying that this could not be a false positive or something but in case it was the real thing, I want people to be aware. When I did a google search, I found this trojan has other names but seems to be an url spoofer in this case. So, I might not be safe even when on a secure site. So please everyone, get the best antivirus you can afford and a firewall too. I'm not sure what the best way to go about this is but I am just wanting to let people know about this recent event.

Back to top
View users profile Send private message
P7755

Mozilla Host
Premium Member

Joined: Aug 02, 2004
Posts: 801

Premium

PostPosted: Sat Dec 25, 2004 10:57 am    Post subject:
Reply with quote

Well, there are firewalls and antivirus programs available on this sites download section. Second, are you sure you were in a secure site? Paypal advises its users to open a new browser everytime you want to go to paypal, and type the adress http://www.paypal.com. in order to avoid going to a fake paypal website. Also, here are some other ways to stay safe when using paypal. Go Here: http://www.paypal.com/cgi-bin/webscr?cmd=xpt/general/SafetyBarLanding-outside


_________________
Get Firefox
Get Paypal for Business
Get Love
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sat Dec 25, 2004 3:38 pm    Post subject:
Reply with quote

You might want to take a look at the following info provided earlier on this site by Apluswebmaster:
http://castlecops.com/pstp391685-.html#391685
http://castlecops.com/t93118-Yet_another_IE_phishing_exploit_discovered.html
And this from Yahoo news:
http://story.news.yahoo.com/news?tmpl=story&cid=1093&ncid=1093&e=4&u=/pcworld/20041220/tc_pcworld/118997


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
goldberry

Cadet
Cadet


Joined: Jul 06, 2004
Posts: 4
Location: USA

PostPosted: Sat Dec 25, 2004 4:06 pm    Post subject: Thanks for Info new type of phishing?
Reply with quote

Quote:
I just reread the Secunia Advisory, now it makes sense.
A spoofed link within a trusted web site
Thanks so much Oldfrog and P7755. As soon as Christmas is over, I wll be scrutinizing all the new info in the links you guys provided on this and will be figuring out my best source of action. I was using my yahoo browser which of course as you guys probably know is really just IE 4 on xp sp2. My mozilla doesn't really let me surf eBay so great as it is configured for complete safety and I use it for all my browsing except certain sites. Again, I want to say thanks. It seems that I spend more and more time on safety issues and research. In my case, I like research and I like a challenge so it is not as bad as it could be since I take the attitude that these baddies aren't going to beat me. But it consumes a lot of time and with my limited knowledge of technologies a lot of intellectual energy. It has taken some of the joy out of browsing and time I could devote to learning other software and computer activities that I enjoy more. Again, I want to say Thanks and Happy Holidays, Goldberry

Back to top
View users profile Send private message
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Sun Dec 26, 2004 2:47 pm    Post subject:
Reply with quote

it is quite possible you got it from somewhere else, but it was triggered when you went to Paypal. Please make sure your machine is clean and then change your passwords to ensure that information hasn't been sent back to someone trying to rip you off.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer