[Security] Google Chrome look-alike malware



No Deposit

No Deposit

No Deposit Bonus Casino South Africa: How the Offers Really Work A no deposit bonus casino in South Africa is ...
Free Spins

Free Spins

Free Spins Casino Bonuses South Africa: Types, Terms and How to Claim Them Free spins bonuses credit a set number ...
Mobile

Mobile

South African Mobile Casinos: Access, Apps and What Works on a Phone South African mobile casinos are offshore casino sites ...
Pay by Phone

Pay by Phone

Pay by Phone Bill Casinos South Africa: Why the Method Does Not Work and What to Use Instead Pay by ...
OTT Voucher

OTT Voucher

OTT Voucher Online Casino South Africa: How Deposits Work An OTT Voucher online casino in South Africa is an offshore ...
Rand

Rand

South African Online Casinos Accepting Rand: What ZAR Pricing Really Means South African online casinos accepting Rand are offshore sites ...
Instant EFT

Instant EFT

Instant EFT Casino South Africa: How Deposits and Withdrawals Work Instant EFT is a real-time bank payment used at casino ...
High Roller

High Roller

High Roller Casinos in South Africa: VIP Shortlist, Limits and Safety Guide High roller casinos in South Africa are offshore, ...
New

New

New Online Casinos South Africa: How to Check a New Site Before You Play New online casinos in South Africa ...
Bonuses SA

Bonuses SA

Online Casino Bonuses in South Africa: How to Read the Terms Before You Claim Online casino bonuses in South Africa ...
tehƧP@ƦKly�ANK� -Ⅲ�
10-25-2015, 06:29 AM
http://www.pcworld.com/article/2994778/security/tricky-new-malware-replaces-your-entire-browser-with-a-dangerous-chrome-lookalike.html
Related Article: https://blog.malwarebytes.org/online-security/2015/10/efast-browser-hijacks-file-associations/

Apparently, based on PUP (Potentially Unwanted Programs) installations (most likely third-party sites with their own installers),
your Google Chrome can potentially get hijacked by malware.

Easy signs of this happening?
Chrome taking over default file associations.

This one hijacks these file-associations:

gif
htm
html
jpeg
jpg
pdf
png
shtml
webp
xht
xhtml

Naturally, most operating systems have their own picture viewers installed before you install other viewers (XNView, etc).

It can also hijack URL’s.

The same is done for these URL-associations:

ftp
http
https
irc
mailto
mms
news
nntp
sms
smsto
tel
urn
webcal

Why this matters:

As pseudonymous infosec expert SwiftOnSecurity noted, it�s a testament to Chrome�s security against in-browser malware that attackers are now trying to overwrite the program completely. With Windows looking like the weaker link, users will want to be extra careful when using software installers from untrusted sources.

In any case, the browser does clearly identify itself when visiting the About page from the Settings menu (chrome://chrome/).
PCRisk has detailed removal instructions (https://www.pcrisk.com/removal-guides/9480-ads-by-efast-browser#!prettyPhoto).

Just an informational post to warn those who might have fallen victim.
Always trust it when it comes to Malwarebytes!


Scroll to Top