anandk
Distinguished Member
If users wanted to download WinRAR, the popular archiver tool to process RAR and ZIP files, where would they go? Chances are, they’d type in the name of the tool itself and just add .com (www.winrar.com) in their browser’s address bar. Unbeknownst to them, however, the said site is not the official site from which the legitimate tool could be downloaded–that would be www.rarlab.com, actually.
*extracare.trendmicro-europe.com/tm/core/global/images/diary/cc890aae83e12f3c7adbe4abcefc1772_winrar.gif
When they click on “Download Winrar”, a link to "ench dot ircfast dot com" would appear. Finally, another Web page, wholly in French, would display 11 supposed versions of WinRAR... In truth, these are 11 files that are all detected by Trend Micro as trojan TROJ_STARTPA.QC. !!!
Source : *blog.trendmicro.com/a-winrar-lose-situation/
*extracare.trendmicro-europe.com/tm/core/global/images/diary/cc890aae83e12f3c7adbe4abcefc1772_winrar.gif
When they click on “Download Winrar”, a link to "ench dot ircfast dot com" would appear. Finally, another Web page, wholly in French, would display 11 supposed versions of WinRAR... In truth, these are 11 files that are all detected by Trend Micro as trojan TROJ_STARTPA.QC. !!!
Source : *blog.trendmicro.com/a-winrar-lose-situation/