ThreatFire Research Blog Home
 
 
« Hacktivist Group Anonymous Targets Australian Parliament
A Zbot Botnet Dubbed The “Kneber” Botnet »

Windows Defender 2010 FakeAv at the Top of this Morning’s List

The group behind “live-windowsantivirus. com” is having a very busy morning distributing Rogueware XP Internet Security 2010. We grabbed some snapshots for you of the current incarnation of the malware, since users appear to be falling for it in large numbers. The full window and the balloon popup stating “System Danger! Your system security is in danger” must be convincing…

2.System_Danger

Fake scan results are presented immediately…

1.XP_InternetSec

As we have been presenting for the past several years, the user is tipped off that something is amiss when their software claims it is “unregistred”, see the window’s title bar.

3.Attention_Danger

Following the “Attention: DANGER!” message, the Windows user may attempt to open Internet Explorer. The FakeAv has modified the browser and instead pops up a window, claiming the system is infected with Trojan-BNK.Win32.Keylogger.gen, recommending activation of XP Internet Security 2010…

4.Firewall_Alert

When the user attempts to activate the phony product, a purchase window for “Windows Defender 2010″ appears…

5.WindowsDefender2010

Running down the side of the page, they make fraudulent claims to have won awards from West Coast Labs and Virus Bulletin:

6.PhonyAwards

Entering personal information into the form POSTS the information to “live-windowsantivirus. com” (the domain is registered in Turkey, while the site is hosted in the US at 206.217.211 .243). We recommend you avoid entering any personal information and clean up the infection instead:

7.2YearLicense

ThreatFire prevents it from running on users’ systems as “Trojan.FakeAv”.

This entry was posted on Tuesday, February 16th, 2010 at 12:37 pm and is filed under Dropper, FakeAlert, Rogueware, Social Engineering, Trojan, Uncategorized, Undetected malware. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

10 Responses to “Windows Defender 2010 FakeAv at the Top of this Morning’s List”

  1. Bobby says:
    February 21, 2010 at 9:33 am

    Yes I have some trouble with a hackers,but treatfire is excellent!

  2. Sam says:
    February 22, 2010 at 11:11 am

    OMG! This malicious Trojan attacked my computer, infiltrating AVG anti-virus. Threatfire removed the Trojan quickly! I’m so grateful to you Threatfire!

  3. Carl B. says:
    February 24, 2010 at 1:15 pm

    ThreatFire has been protecting my windows xp and now I’ve installed it on my Vista notebook .
    I also have PC Tools Firewall Plus protecting my computers ….thank you for keeping me safe !

  4. Al says:
    February 24, 2010 at 3:02 pm

    PC Tools (T-Fire) is the best for average person just looking to protect their investment. THANKS!

  5. Cori says:
    February 25, 2010 at 9:06 am

    My laptop was attacked by this virus and, although I was able with several programs to remove most instances, it had already managed to hide itself in my registry. After a nightmare week, during which I had to actually ship my laptop back to HP for repairs, during which they did less than nothing and returned my laptop in worse condition then when they got it, I was finally able to reinstall my OS and all of my needed programs.

    Happily I have now found Threatfire, so hopefully this type of attack is in my past. My boyfriend’s computer received a similar attack last night, so the first thing we are doing is to install Threatfire, and hopefully that will take care of the problem.

  6. MPC says:
    February 28, 2010 at 2:16 pm

    FYI – **Most** FakeAV programs like XP/Vista/Windows 7 Antivirus/Internet Security 2010 will NOT allow you to install an antivirus or malware removal program to remove the infection AFTER the infection has already gotten into your computer.

  7. Amber says:
    March 6, 2010 at 2:37 am

    I got hit with this last month while browsing deviantART. My mom was able to get rid of it by stopping it from running at startup and doing a System Restore.
    If this thing’s coming from Turkey, it might be funding terrorism.

  8. Linda says:
    March 6, 2010 at 8:01 am

    My laptop was invaded and the result was that everytime I try to log on, it goes in a circle and closes. Has anyone else had this problem? Where did it come from?

  9. Linda says:
    March 6, 2010 at 8:02 am

    Actually, it happened immediately after I looked at a game on Facebook.

  10. jacksonville repair computers says:
    March 8, 2010 at 1:34 am

    I’m always looking into stuff on information that I do not know about. It is tough to search things that you don’t know of, because what do you search for? ;) Your blog is the type of thing I love to read about regarding something new to me. Great post! Thanks.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).