<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">toykofalcon malware</title>
  <updated>2017-09-26T19:51:22+01:00</updated>
  <generator uri="http://framework.zend.com" version="1.12.20">Zend_Feed_Writer</generator>
  <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1481"/>
  <link rel="self" type="application/atom+xml" href="https://www.augwessex.org.uk/discussions/view/1481/feed"/>
  <id>https://www.augwessex.org.uk/discussions/view/1481</id>
  <author>
    <name>AUGW</name>
    <email>info@augwessex.org.uk</email>
    <uri>https://www.augwessex.org.uk/</uri>
  </author>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[toykofalcon malware]]></title>
    <updated>2017-09-25T21:27:22+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1481#7027"/>
    <id>https://www.augwessex.org.uk/discussions/view/1481#7027</id>
    <author>
      <name>David Fleetwood</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">I found an app. with this name a couple of days ago in my Apps folder and as it wasn't something I'd downloaded intentionally I ditched it and emptied the trash. It seems it is a piece of malware. I also found a Safari extension in this name which I have also now removed.  <xhtml:br/>
Do I need to do anymore to remove the threat this nasty poses? I have no idea how I acquired it but recently I have been getting an increased number of emails notifications from my ISP (John Lewis) saying that emails sent to me have been quarantined because they contained a virus, might the two be linked?</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: toykofalcon malware]]></title>
    <updated>2017-09-26T17:32:53+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1481#7031"/>
    <id>https://www.augwessex.org.uk/discussions/view/1481#7031</id>
    <author>
      <name>Mick Burrell</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">I think that's a typo - it should be tokyofalcon. There are various reports online including what you need to do to get rid of it. I've no idea how legitimate or trustworthy these sites are but I found them easily:<xhtml:br/>
<xhtml:br/>
<xhtml:a href="https://www.pcrisk.com/removal-guides/11568-search-tokyofalcon-com-redirect-mac" target="blank">Remove - Version 1</xhtml:a><xhtml:br/>
<xhtml:br/>
<xhtml:a href="https://malwarefixes.com/remove-search-tokyofalcon-com-mac-os-x/" target="blank">Remove - Version 2</xhtml:a></xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: toykofalcon malware]]></title>
    <updated>2017-09-26T19:51:22+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1481#7034"/>
    <id>https://www.augwessex.org.uk/discussions/view/1481#7034</id>
    <author>
      <name>David Fleetwood</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks Mick. I followed the instructions in Version 2 which were very similar to Version 1 and removed all the suspicious files in the library folders mentioned - there were several.  I have not run the Adware Removal Tool they encourage you to get  as no doubt this is where they make their money! Hopefully I have done enough to get rid of the problem.</xhtml:div>
    </content>
  </entry>
</feed>
