ThreatFire Research Blog Home
 
 
« Wachovia Link
Microsoft batch of updates, Flash »

Seeing Triple?


And here we thought our vision was bad the other day when we were dizzy from seeing double.

And here we thought our vision was bad the other day when we were dizzy from seeing double.

And here we thought our vision was bad the other day when we were dizzy from seeing double.

Today and yesterday, some of our users were duped into seeing triple. Wav2008.com, sav2008.com, and vav2008.com all appear to hawk pretty much the same stuff. When we download and run each, we get the same misleading scam.
Here is a shot of the wav.exe gui after installing the product and running the scanner. The machine was infected and hundreds of malware and infected files resided on the system. The scanner claims to have found a couple cookies (which are pretty standard for any activity on the web) and some generic names:

Another window appears, reporting the 17 infections that it found and providing standard scary messages:

Any user looking to clean up the “Threats” is prompted with another dialog box for payment:

Running the setup on several other clean systems resulted in pretty much the same phony messages. The software will state that any system it is installed on is infected and payment is required to clean the infections up.
Here is a nifty control panel icon that they add, mirroring the Windows Security Center icon that is shipped by Microsoft:

One unfortunate thing that the distributors just forget to mention on the site is that uninstall functionality is missing from the free scan software, or should I say scam software. Because of this minor oversight, the software repeatedly displays nag windows to the user that a “Blaster/Sasser” attack has been detected, and multiple other infections have been found. Here is the add/remove applet on a system with the software installed, showing the lack of ease for uninstallation:

We’ll get back to this topic when we see more than a dozen at a time.

One last note on this malware’s behavior — at runtime the software sets global hooks. This activity can be a major problem when you don’t know or trust the source. Bill Mullins’ blog posted some information suggesting “There have been some reports indicating that XP Antivirus 2008 has the potential to capture and transmit personal and financial information, although this remains largely unverified”. Well, with the global hooks this software sets, the functionality is there to collect arbitrary information off the machine. We have not witnessed this software collecting arbitrary information off of the system and sending it home.

This entry was posted on Thursday, June 5th, 2008 at 9:54 am and is filed under FakeAlert, Social Engineering. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

2 Responses to “Seeing Triple?”

  1. Wao says:
    June 8, 2008 at 7:41 am

    First, thank you for your developers’ hard work. ThreatFire is much better than its origin – Cyberhawk.

    But, there is one problem I really concern about. It’s about threat list.
    When I set the “Schedule Scan” and it finished work, TF always told me there were some threats in my system but never told me what the threats were.

    The only way I can do is re-scanning, then I know what the threats exactly are.

    I wish your dear developers can fix this problem as soon as possible.

    Thank you sincerely !
    A ThreatFire Fan

  2. ThreatFire Blogger says:
    June 11, 2008 at 11:04 am

    Hi Wao, Thanks so much for the compliment. It’s good to hear from a satisfied user.

    Sorry to hear about the scanner issue you are seeing. Our qa/support team has looked at the issue and is working on it.
    Please, in the future, post support issues on the PC Tools ThreatFire forum, the link is here:
    http://www.pctools.com/forum/
    You will get a quick response.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).