Free removal tool for bank password malware

Pro

17 January 2011

The Backdoor.Lavandos.A malware has been identified as a tool to discreetly steal FTP and e-banking passwords and is primarily used by Russian and Ukrainian institutions. Lavandos will also steal personal data from accounts on the infected computer.

Help is at hand in the form of a free removal tool from security company BitDefender.

When a computer is infected with Backdoor.Lavandos.A, it will generate, for each browser found, a ‘setupapi.dll’ in the installation root folder for Mozilla Firefox, Opera and Internet Explorer. This will enable easy manipulation of browser functions in order to import certificates or to accept a self-signed certificate as being trusted. Users infected with Backdoor.Lavandos.A are at risk of disclosing sensitive information related to e-banking as well as having their FTP accounts stolen by cybercriminals involved in malware distribution.

 

advertisement



 

“What is particularly interesting about this e-threat is the fact that its driver component will not remain written on the disk longer than necessary,” said Catalin Cosoi, head of the BitDefender Online Threats Lab. “Instead it will be stored in the Windows Registry immediately after completing its task, ensuring it keeps a low profile.”

The free Lavandos removal tool can be downloaded from the Downloads section of www.MalwareCity.com, a BitDefender initiative for the software security community and a free resource for those interested in their online security.

While the removal tool is free to all, BitDfender is keen to emphasise that its own antivirus and antimalware products have included protection against the attack from its emergence.

Read More:


Back to Top ↑