Archive for the ‘FakeAlert’ Category

Malware Attacks on Windows 7

Thursday, October 22nd, 2009

Yesterday’s release of Windows 7 brings with it a different playground for malware.


If reviewer predictions are realized, the platform will overtake Windows XP as the Windows OS of choice in high volume. Which provides a whole new platform of interest and attention from money making malware writers. It is inevitable that they will shift their attention to the newest defenses implemented in the most widely deployed platform.


The most common single piece of malware run on Windows 7 Rtm systems, as observed in the ThreatFire Community to-date, has been Protection System FakeAv variants and its droppers. The dropper is usually a part of a crack or keygen distributed at crack sites and over P2P. It drops out multiple other unwanted components, including the FakeAv. It is a common thing to have seen in the past on other platforms. What is different here, is that User Account Control, a feature introduced in Windows Vista, has been reviewed and modified, newly delivered with 7.

At runtime, the Windows 7 related scareware files are dropped to disk and the dropper creates some porn-related shortcuts on the desktop. The offending dropper makes registry key creations to ensure persistence across reboots without a peep from UAC in its default settings, even when logged in as a Standard User. Another executable responsible for many of the popups is copied to the profile directory. A phony scan is kicked off (thousands of pieces of malware were stored on the system and all were not detected), and two hard coded detections are displayed. And no, there isn’t a legitimate vendor that maintains malware family names as variants of “GayCodec”:


Multiple pop-ups appear for phony malware detections and payment/activation. All without a peep from Windows 7 UAC. At reboot, the malware persists, restarts, and performs its worthless rescan again, this time spoofing messages from the Windows firewall with a randomized list of malware that are not running on the system:


It’s reported to attempt uninstall on other security products, which was not observed on lab machines.

All in all, the release seems to be a hit. As volume picks up, most likely so will Windows 7-targeting malware. Users should be aware of scams like this one and always purchase software from legitimate vendors. And install a behavioral layer of protection over and above UAC on your system like ThreatFire, which runs well on Windows 7 and keeps your system protected.

NY Times FakeAv Banner Ads Certainly not New

Monday, September 14th, 2009

The banner ads allegedly rotating through the NY Times website over the weekend delivered FakeAv/Rogueware from servers that have been delivering the same stuff since around July 19th. The current Url over the weekend was protection-check07. com, but it changes frequently.

The ThreatFire community has seen this stuff effectively prevented on desktops using a variety of names since the servers have been delivering the FakeAv, also known as Downloader.MisleadApp, Trojan.Fakeavalert, XPAntivirus and Trojan:Win32/FakeXPA. Here are just a few of the resource variations that ThreatFire has identified over the past few months:

88.198.107.25 /DOWNLOAD/ANTIVIRUS-5920E_2007.EXE
88.198.107.25 /DOWNLOAD/ANTIVIRUS-E92EFB7_2024-2.EXE
88.198.107.25 /DOWNLOAD/ANTIVIRUS-8023A_2024-2.EXE

94.102.51.26 /DOWNLOAD/INSTALL-C8D161_2006-31.EXE
94.102.51.26 /DOWNLOAD/SETUP-A3B7FBB_2024-3.EXE
94.102.51.26 /DOWNLOAD/SETUP-3985EC_2009-2152.EXE

91.212.107.5 /DOWNLOAD/ANTIVIRUS-9F83_2024-5.EXE
91.212.107.5 /DOWNLOAD/INSTALL-9EC30A_2006-71.EXE
91.212.107.5 /DOWNLOAD/INSTALL-C22753_2004.EXE

These servers are hosted in Germany, the Netherlands, and Cyprus, but their victims are located throughout the world. In this case, potentially where-ever NY Times readers may be located. Be sure to add a behavioral based security solution to your system. The banner ads seem to have been acted on quickly, as there has been no additional reports and there have been no further identifiable malicious banners.

Total Security and pav.exe

Monday, August 31st, 2009

Previous posts showed spam-based scams attempting to deliver a payload named “pav.exe” onto your system. The scam is continuing with the title “Total Security” for the familiar scareware messages. Be aware that there is a legitimate security suite that includes those words in its name, but this scam is not that legitimate package. You can recognize the fake scan with phony detections here:

Phony scan offering and immediate scan requirement here:
“Warning!!! Your system requires immediate anti viruses scan! Total Security can perform fast and free virus and malicious software scan of your computer .”

Full phony detection message here:
“Harmful and malicious software detected. Such programs may damage your computer and steal your private information. Online Security Scanner requires Total Security components to repair your computer. Please click OK to download and install Total Security tool.”

Today and yesterday’s most active domains/ip addresses included:
88.198.120.177
antispyware-scanner2 .com
antispyware-scanner5 .com
antivirus-online-scan7 .com
best-antivirus9 .com
live-virus-scanner3 .com
online-best-scanv3 .com
premium-antispy-scanv3 .com
premium-antispy-scanv7 .com
professionalcomputerscanv2 .com
safeonlinescannerv4 .com
safeonlinescanv4 .com
secure-spyware-scannerv3 .com

91.212.127.200
antispyware-scanner2 .com
antispyware-scanner5 .com
antivirus-online-scan7 .com
best-antivirus9 .com
live-virus-scanner3 .com
professionalcomputerscanv2 .com
safeonlinescannerv4 .com
safeonlinescanv4 .com

88.198.81.153
antivirus-scannerv17 .com
best-security-scanv8 .com
bestantispywarescanv4 .com
professionalspywarescanv8 .com
professionalvirusscanv3 .com

78.46.251.43
antivirus-online-scan5 .com
antivirus-scannerv12 .com
antivirus-scannerv15 .com
getyourantivirusv3 .com

83.133.126.201
antivirus-scannerv17.com
bestantispywarescanv4.com
professionalspywarescanv8.com
professionalvirusscanv3.com
protectedsecurityaudit.cn

ThreatFire preventions for this scareware/rogueware payload continue to be on the rise. Before installing any software, be sure to inform yourself by looking into opinions and reviews of legitimate products.