hxxp://q84.isutv.com/wap715-abuibrahim12.html
hxxp://ps51.isutv.com/wap565-abuibrahim12.html
hxxp://ps51.isutv.com/wap84-cherrytoons.html
hxxp://q84.isutv.com/wap363-query-letter.html
hxxp://ps51.isutv.com/wap780-whippedwomen.html
hxxp://ps51.isutv.com/wap293-dr-emma-starr.html
hxxp://q84.isutv.com/wap561-bnz.html
hxxp://q84.isutv.com/wap895-dmaiv.html
hxxp://q84.isutv.com/wap632-unesco.html
Each of the pages would redirect you tothe following rogue antivirus pages:
hxxp://best-virus-scanner4.com/scan1/?pid=111&engine=pHT3zjjyMjE2Mi4xMzEuMjQmdGltZT0xMjUuMIEMPAZO
hxxp://fast-virus-scan9.com/scan1/?pid=111&engine=pHT22jzyMjE2Mi4xMzEuMjQmdGltZT0xMjUuMkEMPAlO
The web page displays a classic fake explorer page giving an impression that your hard-disk partitions are being scanned and malware was found in the computer.
Clicking anywhere around the page, will prompt you download a new trojan named Antivirus_111.exe which at the time I write this blog entry has no detections by any antivirus.
The file when uploaded on VirusTotal, produced the following results:
File Antivirus_21_1_.exe received on 2009.09.06 07:48:07 (UTC) | |||
Antivirus | Version | Last Update | Result |
a-squared | 4.5.0.24 | 2009.09.06 | - |
AhnLab-V3 | 5.0.0.2 | 2009.09.05 | - |
AntiVir | 7.9.1.8 | 2009.09.04 | - |
Antiy-AVL | 2.0.3.7 | 2009.09.04 | - |
Authentium | 5.1.2.4 | 2009.09.05 | - |
Avast | 4.8.1351.0 | 2009.09.05 | - |
AVG | 8.5.0.409 | 2009.09.05 | - |
BitDefender | 7.2 | 2009.09.06 | - |
CAT-QuickHeal | 10.00 | 2009.09.05 | - |
ClamAV | 0.94.1 | 2009.09.06 | - |
Comodo | 2204 | 2009.09.06 | Heur.Packed.Unknown |
DrWeb | 5.0.0.12182 | 2009.09.06 | - |
eSafe | 7.0.17.0 | 2009.09.03 | - |
eTrust-Vet | 31.6.6721 | 2009.09.04 | - |
F-Prot | 4.5.1.85 | 2009.09.05 | - |
F-Secure | 8.0.14470.0 | 2009.09.05 | - |
Fortinet | 3.120.0.0 | 2009.09.06 | - |
GData | 19 | 2009.09.06 | - |
Ikarus | T3.1.1.72.0 | 2009.09.06 | - |
Jiangmin | 11.0.800 | 2009.09.06 | - |
K7AntiVirus | 7.10.837 | 2009.09.05 | - |
Kaspersky | 7.0.0.125 | 2009.09.06 | - |
McAfee | 5732 | 2009.09.05 | - |
McAfee+Artemis | 5732 | 2009.09.05 | - |
McAfee-GW-Edition | 6.8.5 | 2009.09.06 | - |
Microsoft | 1.5005 | 2009.09.06 | - |
NOD32 | 4399 | 2009.09.05 | - |
Norman | 6.01.09 | 2009.09.04 | - |
nProtect | 2009.1.8.0 | 2009.09.06 | - |
Panda | 10.0.2.2 | 2009.09.05 | - |
PCTools | 4.4.2.0 | 2009.09.04 | - |
Prevx | 3.0 | 2009.09.06 | - |
Rising | 21.45.14.00 | 2009.09.01 | - |
Sophos | 4.45.0 | 2009.09.06 | - |
Sunbelt | 3.2.1858.2 | 2009.09.05 | - |
Symantec | 1.4.4.12 | 2009.09.06 | - |
TheHacker | 6.3.4.3.396 | 2009.09.04 | - |
TrendMicro | 8.950.0.1094 | 2009.09.05 | - |
VBA32 | 3.12.10.10 | 2009.09.05 | - |
ViRobot | 2009.9.4.1919 | 2009.09.04 | - |
VirusBuster | 4.6.5.0 | 2009.09.05 | - |
Additional information | |||
File size: 167424 bytes | |||
MD5 : 3aeef8ccec46822d91c97ed92f8a4af2 | |||
SHA1 : 9e310ffad459fe3a10544d6ee78403a3b382891d | |||
SHA256: b2d842f4ebf1561429a0d84929ceeda2c7c5a7f850c2fd66ac4fa2ea6b6d6f15 |
http://www.virustotal.com/analisis/b2d842f4ebf1561429a0d84929ceeda2c7c5a7f850c2fd66ac4fa2ea6b6d6f15-1252223287
Upon executing the file, the following gui appears:The program then automatically installs a fake antivirus called "Total Security":
The malware creates the following folders:
c:\program files\common files\TSUninstall
c:\program files\TS
It also creates the following file:
C:\WINDOWS\system32\iehelpmod.dll
The following registry keys have been added:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}]
&IE Help - C:\WINDOWS\system32\iehelpmod.dll [2009-09-06 335360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TS"=C:\Program Files\TS\tsc.exe [2009-09-06 1542176]
[HKEY_USERS\S-1-5-21-725345543-484763869-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\TS]
If you attempt to uninstall the rogue antivirus, it will show up the following window in order to lure unwary users to purchase their fake product:
I have uploaded the file C:\Program Files\TS\tsc.exe on virustotal which showed that Mcafee is the only antivirus that was able to detect it:
File tsc.exe received on 2009.09.06 11:48:22 (UTC) | |||
Antivirus | Version | Last Update | Result |
a-squared | 4.5.0.24 | 2009.09.06 | - |
AhnLab-V3 | 5.0.0.2 | 2009.09.05 | - |
AntiVir | 7.9.1.8 | 2009.09.06 | TR/Crypt.ZPACK.Gen |
Antiy-AVL | 2.0.3.7 | 2009.09.04 | - |
Authentium | 5.1.2.4 | 2009.09.05 | - |
Avast | 4.8.1351.0 | 2009.09.05 | - |
AVG | 8.5.0.409 | 2009.09.06 | - |
BitDefender | 7.2 | 2009.09.06 | - |
CAT-QuickHeal | 10.00 | 2009.09.05 | - |
ClamAV | 0.94.1 | 2009.09.06 | - |
Comodo | 2204 | 2009.09.06 | - |
DrWeb | 5.0.0.12182 | 2009.09.06 | - |
eSafe | 7.0.17.0 | 2009.09.03 | - |
eTrust-Vet | 31.6.6721 | 2009.09.04 | - |
F-Prot | 4.5.1.85 | 2009.09.05 | - |
F-Secure | 8.0.14470.0 | 2009.09.06 | - |
Fortinet | 3.120.0.0 | 2009.09.06 | - |
GData | 19 | 2009.09.06 | - |
Ikarus | T3.1.1.72.0 | 2009.09.06 | - |
Jiangmin | 11.0.800 | 2009.09.06 | - |
K7AntiVirus | 7.10.837 | 2009.09.05 | - |
Kaspersky | 7.0.0.125 | 2009.09.06 | - |
McAfee | 5732 | 2009.09.05 | FakeAlert-HP |
McAfee+Artemis | 5732 | 2009.09.05 | FakeAlert-HP |
McAfee-GW-Edition | 6.8.5 | 2009.09.06 | Trojan.Crypt.ZPACK.Gen |
Microsoft | 1.5005 | 2009.09.06 | - |
NOD32 | 4399 | 2009.09.05 | - |
Norman | 6.01.09 | 2009.09.04 | - |
nProtect | 2009.1.8.0 | 2009.09.06 | - |
Panda | 10.0.2.2 | 2009.09.06 | - |
PCTools | 4.4.2.0 | 2009.09.06 | - |
Prevx | 3.0 | 2009.09.06 | - |
Rising | 21.45.14.00 | 2009.09.01 | - |
Sophos | 4.45.0 | 2009.09.06 | - |
Sunbelt | 3.2.1858.2 | 2009.09.05 | - |
Symantec | 1.4.4.12 | 2009.09.06 | - |
TheHacker | 6.3.4.3.396 | 2009.09.04 | - |
TrendMicro | 8.950.0.1094 | 2009.09.05 | - |
VBA32 | 3.12.10.10 | 2009.09.05 | - |
ViRobot | 2009.9.4.1919 | 2009.09.04 | - |
VirusBuster | 4.6.5.0 | 2009.09.05 | - |
Additional information | |||
File size: 1542176 bytes | |||
MD5...: 47f48d75791e9ff4831b0e4a553c5569 | |||
SHA1..: 3a1f8a2186611e0c3bcf53cc650307dd5a6bbe82 | |||
SHA256: a7173500bd783ef55d520cb4c9cdd235a250437e639ed589ac99855d65324b5f | |||
ssdeep: 24576:L6x4SD2YP9PeJaSl2eiaQtXOstG0Bu/SCoIxFViKsSKlRZMXK:G4Si2Op2 TaQtestpiUSaZ |
http://www.virustotal.com/analisis/a7173500bd783ef55d520cb4c9cdd235a250437e639ed589ac99855d65324b5f-1252237702
I have also uploaded the associated file iehelpmod.dll on virustotal and no definitions have been created for this trojan yet:
File iehelpmod.dll received on 2009.09.06 10:43:15 (UTC) | |||
Antivirus | Version | Last Update | Result |
a-squared | 4.5.0.24 | 2009.09.06 | - |
AhnLab-V3 | 5.0.0.2 | 2009.09.05 | - |
AntiVir | 7.9.1.8 | 2009.09.04 | - |
Antiy-AVL | 2.0.3.7 | 2009.09.04 | - |
Authentium | 5.1.2.4 | 2009.09.05 | - |
Avast | 4.8.1351.0 | 2009.09.05 | - |
AVG | 8.5.0.409 | 2009.09.06 | - |
BitDefender | 7.2 | 2009.09.06 | - |
CAT-QuickHeal | 10.00 | 2009.09.05 | - |
ClamAV | 0.94.1 | 2009.09.06 | - |
Comodo | 2204 | 2009.09.06 | - |
DrWeb | 5.0.0.12182 | 2009.09.06 | - |
eSafe | 7.0.17.0 | 2009.09.03 | - |
eTrust-Vet | 31.6.6721 | 2009.09.04 | - |
F-Prot | 4.5.1.85 | 2009.09.05 | - |
F-Secure | 8.0.14470.0 | 2009.09.06 | - |
Fortinet | 3.120.0.0 | 2009.09.06 | - |
GData | 19 | 2009.09.06 | - |
Ikarus | T3.1.1.72.0 | 2009.09.06 | - |
Jiangmin | 11.0.800 | 2009.09.06 | - |
K7AntiVirus | 7.10.837 | 2009.09.05 | - |
Kaspersky | 7.0.0.125 | 2009.09.06 | - |
McAfee | 5732 | 2009.09.05 | - |
McAfee+Artemis | 5732 | 2009.09.05 | - |
McAfee-GW-Edition | 6.8.5 | 2009.09.06 | Heuristic.LooksLike.Trojan.FakeAntivirus.I |
Microsoft | 1.5005 | 2009.09.06 | - |
NOD32 | 4399 | 2009.09.05 | - |
Norman | 6.01.09 | 2009.09.04 | - |
nProtect | 2009.1.8.0 | 2009.09.06 | - |
Panda | 10.0.2.2 | 2009.09.05 | - |
PCTools | 4.4.2.0 | 2009.09.04 | - |
Prevx | 3.0 | 2009.09.06 | - |
Rising | 21.45.14.00 | 2009.09.01 | - |
Sophos | 4.45.0 | 2009.09.06 | - |
Sunbelt | 3.2.1858.2 | 2009.09.05 | - |
Symantec | 1.4.4.12 | 2009.09.06 | - |
TheHacker | 6.3.4.3.396 | 2009.09.04 | - |
TrendMicro | 8.950.0.1094 | 2009.09.05 | - |
VBA32 | 3.12.10.10 | 2009.09.05 | - |
ViRobot | 2009.9.4.1919 | 2009.09.04 | - |
VirusBuster | 4.6.5.0 | 2009.09.05 | - |
Additional information | |||
File size: 335360 bytes | |||
MD5...: 5a07fb253ebefadd26d289ccab379a99 | |||
SHA1..: 0b25e2c20b6e6b08df8f05267710f1ed9325dc32 | |||
SHA256: 73ac8c99e02c5475a55434f574d1ceee0bec2c56e126578fb466fd6f5c6b2c7c |
If you ever get infected with VirusTotal, you can easily get rid of the pest by following these instructions:
1. end process to tsc.exe in taskmgr
2. close all browsers
3. make sure to view hidden files, system files and extensions within folder options
4. browse and delete the following folders:
c:\program files\common files\TSUninstall
c:\program files\TS
5. Run Hijackthis, and select 'do a system scan only', and then place a checkmark beside each of these entries:
O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll
O4 - HKCU\..\Run: [TS] C:\Program Files\TS\tsc.exe
6. Then restart the computer
A. Elshafei
No comments:
Post a Comment