<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; Rogue Software</title>
	<atom:link href="http://blog.novirusthanks.org/tag/rogue-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Massive number of blogs hacked for Blackhat SEO</title>
		<link>http://blog.novirusthanks.org/2010/06/massive-number-of-blogs-hacked-for-blackhat-seo/</link>
		<comments>http://blog.novirusthanks.org/2010/06/massive-number-of-blogs-hacked-for-blackhat-seo/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 00:24:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blackhat SEO]]></category>
		<category><![CDATA[hacked websites]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[security master av]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=2619</guid>
		<description><![CDATA[We noticed a new high number of blogs (more than 60) hacked for massive blackhat SEO strategies used to redirect users to fake scanner pages that will prompt the users to download a rogue security software named Security Master AV. This is a small list of hacked websites we have found that host malicious scripts [...]]]></description>
			<content:encoded><![CDATA[<p>We noticed a new high number of blogs (more than 60) hacked for massive blackhat SEO strategies used to redirect users to fake scanner pages that will prompt the users to download a rogue security software named Security Master AV. This is a small list of hacked websites we have found that host malicious scripts used to capture keywords and redirect users to dangerous websites:</p>
<blockquote><p>
<a href="http://www.urlvoid.com/scan/gubserfarms.com" target="_blank">URLVoid Report</a> gubserfarms. com<br />
<a href="http://www.urlvoid.com/scan/buenapetito.net" target="_blank">URLVoid Report</a> buenapetito. net<br />
<a href="http://www.urlvoid.com/scan/renurestoration.com" target="_blank">URLVoid Report</a> renurestoration. com<br />
<a href="http://www.urlvoid.com/scan/robertsawards.biz" target="_blank">URLVoid Report</a> robertsawards. biz<br />
<a href="http://www.urlvoid.com/scan/practicumgroup.com" target="_blank">URLVoid Report</a> practicumgroup. com<br />
<a href="http://www.urlvoid.com/scan/renedaalder.com" target="_blank">URLVoid Report</a> renedaalder. com<br />
<a href="http://www.urlvoid.com/scan/niteczka.com.pl" target="_blank">URLVoid Report</a> niteczka.com. pl<br />
<a href="http://www.urlvoid.com/scan/deliciouz.com" target="_blank">URLVoid Report</a> deliciouz. com<br />
<a href="http://www.urlvoid.com/scan/calicompras.com" target="_blank">URLVoid Report</a> calicompras. com<br />
<a href="http://www.urlvoid.com/scan/fonet.co.za" target="_blank">URLVoid Report</a> fonet.co. za<br />
<a href="http://www.urlvoid.com/scan/rocahosting.com" target="_blank">URLVoid Report</a> rocahosting. com<br />
<a href="http://www.urlvoid.com/scan/hillarynan.com" target="_blank">URLVoid Report</a> hillarynan. com
</p></blockquote>
<p>When the user search a specific keyword in a search engine, on the first pages we can see websites that contain .php scripts in the /images/ folder &#8230; this looks like a bit suspicious:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">/images/trend.php?page=keyword
Host: www.gubserfarms. com</pre></td></tr></table></div>

<p>As response we get a HTTP/1.1 200 OK and there is a redirection in the META HTTP-EQUIV that points to another dangerous link:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">URL=hxxp://ghostroadpress. com/xredir.php?uid=2033&quot;&gt;</pre></td></tr></table></div>

<p>Most of the hacked websites point to ghostroadpress. com (<a href="http://www.urlvoid.com/scan/ghostroadpress.com" target="_blank">URLVoid Report</a>) and we noticed that it contains always a link to another suspicious website that looks like to be used for statistics:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">ctrash.byethost4. com/tick.php?sub=1&amp;r=</pre></td></tr></table></div>

<blockquote><p>
<a href="http://www.urlvoid.com/scan/ctrash.byethost4.com" target="_blank"> URLVoid Report</a> ctrash.byethost4. com
</p></blockquote>
<p>Now we get redirected again to another URL:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Moved Temporarily
Location: hxxp://www3.smartbestav4. co.cc/?p=p52dc</pre></td></tr></table></div>

<blockquote><p>
<a href="http://www.urlvoid.com/scan/www3.smartbestav4.co.cc" target="_blank"> URLVoid Report</a> www3.smartbestav4. co.cc
</p></blockquote>
<p>It is not over! We get again a redirect to another URL:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Moved Temporarily
Location: hxxp://www1.avscaner-34pr. co.cc/?p=xxx</pre></td></tr></table></div>

<blockquote><p>
<a href="http://www.urlvoid.com/scan/www1.avscaner-34pr.co.cc" target="_blank"> URLVoid Report</a> www1.avscaner-34pr. co.cc
</p></blockquote>
<p>And finally we get the fake scanner page:</p>
<p>&nbsp;</p>
<p><img src="http://img263.imageshack.us/img263/9094/hackedwebsitesforblackh.jpg" alt="Image" title="Fake scanner page" /></p>
<p>&nbsp;</p>
<p>A common action of these fake scanner page is that it is always loaded a .js script that as filename it has an hash:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /107aee58f4ea1267e6735c8fb0c51431bd8c3010411.js HTTP/1.1</pre></td></tr></table></div>

<p>When we click in any place of the fake scanner page we get again redirected to a new page that will prompt the download of the setup file of the rogue security software named Security Master AV.</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Moved Temporarily
Location: hxxp://www2.zonecleaner-87pd. co.cc/zsnd107_2033.php?p=</pre></td></tr></table></div>

<blockquote><p>
<a href="http://www.urlvoid.com/scan/www2.zonecleaner-87pd.co.cc" target="_blank"> URLVoid Report</a> www2.zonecleaner-87pd. co.cc
</p></blockquote>
<p>Here we can see a screenshot of the setup file that is trying to download and install the rogue security software in our system:</p>
<p>&nbsp;</p>
<p><img src="http://img155.imageshack.us/img155/9094/hackedwebsitesforblackh.jpg" alt="Image" title="Setup file of Security Master AV" /></p>
<p>&nbsp;</p>
<p>This is an image of the installed Security Master AV:</p>
<p>&nbsp;</p>
<p><img src="http://img35.imageshack.us/img35/9094/hackedwebsitesforblackh.jpg" alt="Image" title="Security Master AV - GUI" /></p>
<p>&nbsp;</p>
<p>And these are the files created during the installation process:</p>
<p>&nbsp;</p>
<p><img src="http://img155.imageshack.us/img155/8584/hackedwebsitesforblackhc.jpg" alt="Image" title="Security Master AV Files" /></p>
<p>&nbsp;</p>
<p>After the installation finished to install the rogue security software, the program established various connections with these VERY dangerous websites:</p>
<blockquote><p>
<a href="http://www.urlvoid.com/scan/update1.free-guard.com">URLVoid Report</a> update1.free-guard. com/index.php?def387=<br />
<a href="http://www.urlvoid.com/scan/update1.free-guard.com">URLVoid Report</a> update1.free-guard. com/xp_2b2ff.exe<br />
<a href="http://www.urlvoid.com/scan/www1.detector11-pr.co.cc">URLVoid Report</a> www1.detector11-pr. co.cc/hch107_2033.php?p=<br />
<a href="http://www.urlvoid.com/scan/www5.securitymasterav.com">URLVoid Report</a> www5.securitymasterav. com<br />
<a href="http://www.urlvoid.com/scan/secure2.protectzone.net">URLVoid Report</a> secure2.protectzone. net/?abbr=SMAV&#038;pid=3<br />
<a href="http://www.urlvoid.com/scan/report.zoneguardland.com">URLVoid Report</a> report.zoneguardland. com<br />
<a href="http://www.urlvoid.com/scan/report.goodguardz.com">URLVoid Report</a> report.goodguardz. com<br />
<a href="http://www.urlvoid.com/scan/secure1.protect-zone.com">URLVoid Report</a> secure1.protect-zone. com/?abbr=SMAV&#038;pid=3<br />
<a href="http://www.urlvoid.com/scan/report.myfairland.com">URLVoid Report</a> report.myfairland. com<br />
<a href="http://www.urlvoid.com/scan/report1.stat-mx.xorg.pl">URLVoid Report</a> report1.stat-mx.xorg. pl<br />
<a href="http://www.urlvoid.com/scan/report.land-protection.com">URLVoid Report</a> report.land-protection. com
</p></blockquote>
<p>Be always careful while searching for any kind of keywords in Search Engines!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2010/06/massive-number-of-blogs-hacked-for-blackhat-seo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Commander &#8211; Rogue software</title>
		<link>http://blog.novirusthanks.org/2008/12/privacy-commander/</link>
		<comments>http://blog.novirusthanks.org/2008/12/privacy-commander/#comments</comments>
		<pubDate>Thu, 04 Dec 2008 22:13:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Privacy Commander]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=457</guid>
		<description><![CDATA[Privacy Commander is another software that look like a security tool, but it will show you only false virus detections only to puch you into buy the full version. In my case, the malicious software showed me also files that where not present in my system and there was frequently popups that showed me always [...]]]></description>
			<content:encoded><![CDATA[<p>Privacy Commander is another software that look like a security tool, but it will show you only <strong>false virus detections</strong> only to puch you into buy the full version.  In my case, the malicious software showed me also files that where not present in my system and there was frequently popups that showed me always false virus detections that the software claimed to found in my system.</p>
<p>The installer file was named <strong>install.exe</strong> and below there is the report of the scanner:</p>
<blockquote><p>
Report Generated 	4.12.2008 at 23.04.10 (GMT 1)<br />
Time for scan: 	47 seconds<br />
Filename: 	install.exe<br />
File size: 	1693 KB<br />
MD5 Hash: 	ADEA5D67CF489ED35E968B28A5EE422E<br />
SHA1 Hash: 	6D46083580558C81233CD5EB34A0543751F56316<br />
CRC32: 	756827256<br />
Application Type:	Executable (EXE) 32bit<br />
Packer detected:	Nullsoft PiMP Stub [Nullsoft PiMP SFX] *<br />
Self-Extract Archive: 	Nothing found<br />
Binder Detector: 	Nothing found<br />
ASCII Strings: 	View<br />
Detection Rate:	<font color="red">2</font> on 23</p>
<p>Antivirus 	Result<br />
a-squared 	<font color="green">Nothing found!</font><br />
Avira AntiVir 	<font color="green">Nothing found!</font><br />
Avast 	<font color="green">Nothing found!</font><br />
AVG 	<font color="green">Nothing found!</font><br />
BitDefender 	<font color="green">Nothing found!</font><br />
ClamAV <font color="green">	Nothing found!</font><br />
Comodo <font color="green">	Nothing found!</font><br />
Dr.Web 	<font color="green">Nothing found!</font><br />
Ewido 	<font color="green">Nothing found!</font><br />
F-PROT 6 	<font color="green">Nothing found!</font><br />
G DATA 	<font color="green">Nothing found!</font><br />
IkarusT3 	<font color="green">Nothing found!</font><br />
Kaspersky 	<font color="green">Nothing found!</font><br />
McAfee 	<font color="green">Nothing found!</font><br />
MHR (Malware Hash Registry) 	<font color="green">Nothing found!</font><br />
NOD32 v3 	<font color="red">probably unknown NewHeur_PE virus</font><br />
Panda 	<font color="green">Nothing found!</font><br />
QuickHeal 	<font color="green">Nothing found!</font><br />
Solo Antivirus 	<font color="green">Nothing found!</font><br />
Sophos 	<font color="red">Sus/Behav-269</font><br />
TrendMicro 	<font color="green">Nothing found!</font><br />
VBA32 	<font color="green">Nothing found!</font><br />
VirusBuster 	<font color="green">Nothing found!</font>
</p></blockquote>
<p>Some images of the installed software:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/Privacy_Commander_img1.gif" alt="" /></p>
<p><a href="http://blog.novirusthanks.org/wp-content/uploads/Privacy_Commander_img2.gif" target="_blank"><img src="http://blog.novirusthanks.org/wp-content/uploads/Privacy_Commander_img2.gif" alt="" width="650" height="600" /></a></p>
<p>If you are infected by this malicious software and you need to remove it I suggest you to try this remover:  </p>
<p><a href="http://novirusthanks.org/blog/?p=275"><img src="http://novirusthanks.org/images/NVT_Rogue_Remover_DL.gif"/></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/12/privacy-commander/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Spy Protector</title>
		<link>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/</link>
		<comments>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 22:29:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[rogue spyprotector]]></category>
		<category><![CDATA[spy protector]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=189</guid>
		<description><![CDATA[Spy Protector is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim. &#160; Once your computer is infected with this parasite, it will immediately displays security [...]]]></description>
			<content:encoded><![CDATA[<p>Spy Protector is a rogue security software, it is a false anti-spyware application that is generally installed in the user&#8217;s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim.</p>
<p>&nbsp;</p>
<p>Once your computer is infected with this parasite, it will immediately displays security warnings, alerts and system scans stating that your computer is heavily infected. These warnings are all false and are only displayed to make you think your computer is truly infected and that it is necessary to buy the full version of the software to remove the so-called infections.</p>
<p>&nbsp;</p>
<p>Make sure to not fall in this scam, if your computer is infected with Spy Protector, it is recommended to remove it immediately and to scan your system with a real security software.</p>
<p>&nbsp;</p>
<p><b>Symptoms of infection</b></p>
<p>&nbsp;</p>
<ul>
<li> The process srcss.exe is running in your system</li>
<li> Slow computer performance</li>
<li> Repeated security warnings, alerts and system scans</li>
<li> Web sites that suddenly are shown on your desktop</li>
</ul>
<p>&nbsp;</p>
<p>Malicious web sites and urls:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">spy-protector.org</pre></td></tr></table></div>

<p>When the program is executed, it creates the following files:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">%ProgramFiles%\Spy Protector
%UserProfile%\Application Data\install.exe
%UserProfile%\Application Data\shellex.dll
%UserProfile%\Application Data\srcss.exe
%UserProfile%\Application Data\SpyProtector
%UserProfile%\Application Data\SpyProtector\SC_Base_new.dat
%UserProfile%\Application Data\SpyProtector\SC_Config.ini
%UserProfile%\Desktop\Spy Protector.lnk
%UserProfile%\Start Menu\Programs\Spy Protector
%UserProfile%\Start Menu\Programs\Spy Protector\Purchase License.url
%UserProfile%\Start Menu\Programs\Spy Protector\Spy Protector.lnk
%UserProfile%\Start Menu\Programs\Spy Protector\Support Page.url</pre></td></tr></table></div>

<p>The program creates the following registry entries:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">HKCU\Software\Microsoft\Windows\CurrentVersion\SpyProtector
HKCR\*\shellex\ContextMenuHandlers\Spy Protector
HKCR\Directory\shellex\ContextMenuHandlers\Spy Protector
HKCR\Drive\shellex\ContextMenuHandlers\Spy Protector
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Spy Protector</pre></td></tr></table></div>

<p>How to remove XPShield (manual removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Kill all the Spy Protector processes</li>
<li> Unregister all the Spy Protector DLLs</li>
<li> Delete all the Spy Protector files</li>
<li> Delete all the Spy Protector registry entries</li>
</ul>
<p>&nbsp;</p>
<p>How to remove Spy Protector (automatic removal) ?</p>
<p>&nbsp;</p>
<ul>
<li> Download and Install <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/" target="_blank" title="Free Malware Remover">NoVirusThanks Malware Remover</a></li>
<li> Update the database</li>
<li> Click the button Scan</li>
<li> Delete infected files</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/spy-protector-another-rogue-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

