ThreatFire Research Blog Home
 
 
« Ongoing Waledac Botnet and Spam Operation
Microsoft Patch Tuesday 009 »

Tubeplayer.ver.6.exe — Fakealert Downloader Sites

We’ve been watching a long list of domains that serve up whatever filename you give them, but they provide nothing but a good old fashioned Rogueware downloader, which sometimes goes by the family name Trojan-Downloader.Renos, or Trojan.Fakealert. It’s one of the downloaders that fetches and runs the AV2009 and other phony AV software, bombarding a user with shocking popups. Most often, users are redirected to these sites, expecting to download a codec. The filename may look like “tubeplayer.ver.6.exe”. DO NOT DOWNLOAD AND RUN WHAT MAY LOOK LIKE CODEC INSTALLERS FROM THESE SITES:

hxxp://2009download-best-soft.com
hxxp://best-ps-download-4pc.com
hxxp://downloabsecurehere1.com
hxxp://downloabsecurehere2.com
hxxp://downloabsecurehere3.com
hxxp://downloabsecurehere4.com
hxxp://download-all4free.com
hxxp://download-allsoftnow.com
hxxp://download-files-bak.net
hxxp://download-fls.com
hxxp://download-softarch.com
hxxp://download-top-software.com
hxxp://download-top-software.net
hxxp://downloadall-soft-now.com
hxxp://downloadallsoft-now.com
hxxp://downloadallsoftnow.com
hxxp://dwnld-files.com
hxxp://fast-download-base-free.com
hxxp://files-upload-21.com
hxxp://get-files-4free.net
hxxp://get-frsh-files.com
hxxp://go-downloadz-pc-soft.com
hxxp://load-software-dowload.net
hxxp://pure-download-new.net
hxxp://soft-4-you-download.net
hxxp://top-best-software-area.net
hxxp://2009download-best-soft.com
hxxp://best-ps-download-4pc.com
hxxp://downloabsecurehere1.com
hxxp://downloabsecurehere2.com
hxxp://downloabsecurehere3.com
hxxp://downloabsecurehere4.com
hxxp://download-all4free.com
hxxp://download-allsoftnow.com
hxxp://download-fls.com
hxxp://download-softarch.com
hxxp://download-top-software.com
hxxp://download-top-software.net
hxxp://download-top-software.net
hxxp://downloadall-soft-now.com
hxxp://downloadallsoft-now.com
hxxp://downloadallsoftnow.com
hxxp://dwnld-files.com
hxxp://fast-download-base-free.com
hxxp://files-upload-21.com
hxxp://get-frsh-files.com
hxxp://go-downloadz-pc-soft.com
hxxp://load-software-dowload.net
hxxp://pure-download-new.net
hxxp://soft-4-you-download.net
hxxp://top-best-software-area.net

This entry was posted on Thursday, January 8th, 2009 at 12:24 am and is filed under Adware, FakeAlert, Rogueware, Social Engineering, Trojan. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

5 Responses to “Tubeplayer.ver.6.exe — Fakealert Downloader Sites”

  1. RaoSunshine says:
    January 10, 2009 at 10:53 am

    How did you get the tubeplayer.ver.6 trojan horse out of your computer? I think I already did, but I’m not sure and want to try everything I can to make sure.
    Thanks.
    -cp

  2. RaoSunshine says:
    January 10, 2009 at 10:55 am

    Was this from youtube?
    Or a movie/video site? I have been going to both and was trying to figure where I got it so I won’t go there again. And how to be sure it is no longer in my computer!

  3. ThreatFire Blogger says:
    January 12, 2009 at 2:02 pm

    Thanks for the note Rao. ThreatFire so far was not built to be a cleanup tool, but it is effective against the installs from current tubeplayer.ver.6 infections. In the lab on an infected system, we see that the user is prompted to kill four of the components and cleans them up properly. Some non-functional items are left behind by ThreatFire (they won’t run or perform any malicious task): some system tasks that attempt to run files that have been deleted (you can find the “Tasks” applet in your control panel), and a tmp file in the temp directory.
    We’ll explore its cleanup further. Thanks!

  4. David J says:
    January 13, 2009 at 6:49 am

    There is a tubeplayer icon on my desktop but it appears to be a non existent file… The file size says 0 (Zero) and I can’t find anything with any of the latest tools such as windows defender…
    Would tubeplayer normally appear after a scan?
    How do I know that It’s been removed?

  5. ThreatFire Blogger says:
    January 13, 2009 at 11:33 am

    David J-

    If you ran the downloader discussed in this post from one of the listed domains, you most likely would be seeing all sorts of popups and problems already.
    You can find help to evaluate your system on the “Spyware, Adware and Malware Discussion” board at PC Tools’ community forums:
    http://www.pctools.com/forum/index.php

    You may want to install Spyware Doctor and give it a run, if you don’t already have ThreatFire installed.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).