Malware City/Blog/

Aug
07
Filed Under:
WEEKLY REVIEW

BitDefender weekly review – Rogues are sill out there ...

07 August 2009
Another rogue anti-virus (what do you know?) called “System Security”, which provides anything but security for an infected system, is lurking for unknowing users (are there still any out there?). Also in this weeks review is one of those nasty IM worms that send messenger spam which nobody knew where it came from.

Trojan.FakeAV.OT

This new piece of rogue software is promoting "System Security". When executed, the application creates a copy of itself in %appdata%\[random].exe, where [random] is an 8 digit random number. It registers this executable to run at system startup by making changes to the registry and then deletes itself using the batch self-delete technique.

When the e-threat is executed at startup, it will mimic a full system scan alerting the user of numerous infections.  All of them are fake and have only one purpose: make the victim buy the product to "clean" his computer.

A glimpse at System Security

Win32.Worm.IMStealer.A

When executed, the worm makes a copy of itself in %temp%\svchost32.exe and registers the executable to run at system startup.

The worm uses two distinct methods to spread. The first is the autorun.inf method. It creates copies of itself in the root folder of every local drive, network drive and removable drive along with an autorun.inf file which points to the executable.

The second spreading routine is by using instant messengers like Skype, Yahoo! Messenger, Windows Live Messenger, AIM and ICQ.  It searches for opened windows of these applications and filters data (user accounts) from several zones of interest: input boxes, lists, sub-windows. The it will try sending a copy of itself to the user with the name MichaelJackson_WTF.pif. It accomplishes this by  mimicking mouse and keyboard actions.

Information in this article is available courtesy of BitDefender virus researchers: Marius Vanta and Ovidiu Visoiu




Comments:

Guest said on Aug-10-2009 12:39

Thank you once again, it's a great service you are giving the law abiding computer users

mike said on Aug-12-2009 10:20

Does BitDefender sell its product in any US stores? I would rather buy it at retail. Thank you!

Mint said on Aug-13-2009 06:40

This kind of Malware can infect into usb drive and network drive too.
The malware writer use a trick to makes user to download a "fake" security apps.

Comment on this

Name:

Email:

Website:

Your email adress will not be published.