<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>download Archives - Malware Complaints</title>
	<atom:link href="https://malwarecomplaints.info/tag/download/feed/" rel="self" type="application/rss+xml" />
	<link>https://malwarecomplaints.info/tag/download/</link>
	<description>Virus and Malware Removal Guides</description>
	<lastBuildDate>Mon, 06 Nov 2017 18:19:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.2</generator>

<image>
	<url>https://malwarecomplaints.info/wp-content/uploads/2020/11/Malware-Complaints-Logo.svg</url>
	<title>download Archives - Malware Complaints</title>
	<link>https://malwarecomplaints.info/tag/download/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Anime site Crunchyroll Down and hacked to spread malware</title>
		<link>https://malwarecomplaints.info/anime-site-crunchyroll-hacked-spread-malware/</link>
					<comments>https://malwarecomplaints.info/anime-site-crunchyroll-hacked-spread-malware/#respond</comments>
		
		<dc:creator><![CDATA[Boris]]></dc:creator>
		<pubDate>Mon, 06 Nov 2017 11:03:06 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[anime]]></category>
		<category><![CDATA[Crunchyroll]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[streaming app]]></category>
		<category><![CDATA[virus]]></category>
		<guid isPermaLink="false">http://malwarecomplaints.info/?p=1552</guid>

					<description><![CDATA[<p>Couple of days ago, it was revealed that the popular anime website Crunchyroll was down while getting hijacked by hackers that used it to distribute malware to the visitors under the guise that the virus was a desktop streaming application. A statement was issued on the website for visitors to stay away from it until [&#8230;]</p>
<p>The post <a href="https://malwarecomplaints.info/anime-site-crunchyroll-hacked-spread-malware/">Anime site Crunchyroll Down and hacked to spread malware</a> appeared first on <a href="https://malwarecomplaints.info">Malware Complaints</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;">Couple of days ago, it was revealed that the popular anime website Crunchyroll was down while getting hijacked by hackers that used it to distribute malware to the visitors under the guise that the virus was a desktop streaming application. A statement was issued on the website for visitors to stay away from it until the issue gets taken care of. At the moment of writing, it seems that things are back to normal and there’s no longer malware getting distributed through Crunchyroll.</span></p>
<h2 id="crunchyroll-viewer-download-prompt"><strong><span style="font-family: helvetica, arial, sans-serif;">Crunchyroll Viewer download prompt</span></strong></h2>
<p><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;">While the attack was still ongoing, visitors to Crunchyroll were getting greeted by a pop-up download suggestion that promoted what seemed like a desktop steaming application named</span><b> Crunchyroll Viewer</b><span style="font-weight: 400;"> for the site. However, it was eventually discovered that the recommended download had malicious code inside of it. It is still unknown what the exact purpose of the malware is. Some researches have stated that it might be a keylogger virus. If we come across more precise information regarding the purpose of the malware, we will make sure to update this article with whatever new we learn. So far, we do not know the number of users that have fallen for the misleading download suggestion.</span></span></p>
<h1><strong><span style="font-family: helvetica, arial, sans-serif;">Crunchyroll was down but it didn’t get hacked</span></strong></h1>
<p><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;">According to a statement made by the people behind Crunchyroll, their site didn’t actually get hacked but rather became a victim of a DMS hijacking. Apparently, the hackers have been able to obtain access to the Crunchyroll’s Cloudflare account allowing them to redirect the site’s traffic to another address &#8211; a separate website controlled by the cyber-criminals where the malware-distributing download pop-up was displayed to the visitors.</span></p>
<h2 id="removing-the-malware"><strong><span style="font-family: helvetica, arial, sans-serif;">Removing the malware</span></strong></h2>
<p><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;">The good news is that if any of our readers have mistakenly downloaded the Crunchyroll Viewer malware from the Crunchyroll site while the DMS hijack attack lasted, we might be able to help you remove the malicious code from your PC so that it won’t be able to do any harm to you. Apparently, it isn’t all that difficult to get rid of this malware, just follow the next few steps and your PC should soon be clean.</span></p>
<ol>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Press </span><b>Winkey </b><span style="font-weight: 400;">+</span><b> R </b><span style="font-weight: 400;">keys from your keyboard to open the </span><b>Run </b><span style="font-weight: 400;">search box.</span></span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> In </span><b>Run</b><span style="font-weight: 400;">, type </span><b>regedit </b><span style="font-weight: 400;">and hit </span><b>Enter</b><span style="font-weight: 400;">.</span></span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> In the </span><b>Registry Editor </b><span style="font-weight: 400;">that opens, go to this folder </span><b><i>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</i></b><span style="font-weight: 400;">.</span></span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Click on the </span><b>Run </b><span style="font-weight: 400;">folder and look at the right panel &#8211; there should be a key named </span><b>Java</b><span style="font-weight: 400;">. Right-click on it and then select </span><b>Delete </b><span style="font-weight: 400;">to delete it.</span></span></li>
<li><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;"> Now, restart your computer and wait for it to boot back on.</span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Open the </span><b>Start Menu</b><span style="font-weight: 400;"> and copy-paste the next line: </span><b><i>%AppData%</i></b></span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Open the first search result and in the folder that opens, look for a file named </span><b>svchost.exe</b><span style="font-weight: 400;">. Delete this file.</span></span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Next, type in your Start Menu search field and copy-paste this: </span><b><i>notepad %windir%/system32/Drivers/etc/hosts</i></b><span style="font-weight: 400;">.</span></span></li>
<li><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;"> Again, open the first result and scroll down to the button of the notepad file.</span></li>
<li><span style="font-family: helvetica, arial, sans-serif;"><span style="font-weight: 400;"> Look below </span><b>Localhost</b><span style="font-weight: 400;">, see if there are any IP addresses written there. If there are IP’s below </span><b>Localhost</b><span style="font-weight: 400;">, tell us in the comments what they are as you might need to remove them if they are coming from the virus.</span></span></li>
</ol>
<p><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;">After going through with the steps that we just gave you, the shady piece of malware should no longer be on your PC. Once you complete the guide, it is also a good idea to run a full system scan with your antivirus program. If you do not have an antivirus, then we advise you to get one right away and also make sure that it is a reliable and strong one.</span></p>
<p><span style="font-weight: 400; font-family: helvetica, arial, sans-serif;"> One additional piece of advice that we have for you is that you change your passwords on all online accounts that you have in case the Crunchyroll Viewer is an actual keylogger virus as it might have been able to find out what your old passwords were during the time it has been on your computer.</span></p>
<p>&nbsp;</p>
<p>The post <a href="https://malwarecomplaints.info/anime-site-crunchyroll-hacked-spread-malware/">Anime site Crunchyroll Down and hacked to spread malware</a> appeared first on <a href="https://malwarecomplaints.info">Malware Complaints</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://malwarecomplaints.info/anime-site-crunchyroll-hacked-spread-malware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
