Rogue antivirus: a growing problem.

JMH

Banned
Local time
6:42 AM
Messages
6,448
During the past two years we've written many times about programs which pretend to be something that they are not. The most notorious are rogue antivirus solutions – programs which display messages saying the victim machine is infected, even though it is not. These programs neither scan nor clean computers, and they are actually designed to persuade users that their computers are at risk and scare them into buying the "antivirus" product. Such programs are often referred to as "scareware": Kaspersky Lab classifies them as FraudTool, a subset of the RiskWare class.

FraudTool.Win32.SpywareProtect2009: the main window
Such programs are extremely widespread and are increasingly used by cybercriminals. Whereas Kaspersky Lab detected about 3,000 rogue antivirus programs in the first half of 2008, more than 20,000 samples were identified in the first half of 2009.
More -
Viruslist.com - Rogue antivirus: a growing problem
 

My Computer

Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
I ran into 3 of those last night while searching google. The very first link I clicked on popped up a fake antivirus scan and then tried to download a file to my computer. The problem is getting very bad!
 

My Computer

Computer Manufacturer/Model Number
Self Build
OS
Windows 7 Ultimate 64bit
CPU
Intel Xeon 3110 (Same as Core 2 Duo E8400) 3.0Ghz @ 3.6Ghz
Motherboard
Gigabyte EX38-DS4
Memory
8GB G. Skill PC2-8500
Graphics Card(s)
PALiT GeForce 9600 GT PCI Express 2.0
Sound Card
OnBoard - Realtek ALC889A High Definition Audio
Monitor(s) Displays
Dell 24" LCD
Screen Resolution
1920x1200
Hard Drives
Western Digital VelociRaptor WD3000GLFS - 300GB | Western Digital Caviar SE16 WD7500AAKS - 750GB | LaCie d2Next-Quadra external - 1TB
PSU
Corsair HS620W
Case
Lian Li PC-V1100b Plus II
Cooling
Thermalright Ultra 120 eXtreme
Keyboard
Logitech
Mouse
Logitech MX Laser
Internet Speed
SLOW - HughesNet Satellite Internet - SUCKS!
Never install anything which isn't well known to you, simple.

If it's unfamiliar, and you're uncertain - Google it... :rolleyes:
 

My Computer

Computer Manufacturer/Model Number
Custom built machine
OS
W7 x64
CPU
Intel Q9300 2.5Ghz Quad LGA775 (Would like Q9650)
Motherboard
Gigabyte GA-EP45T-UD3R (F6 Bios)
Memory
4Gb OCZ Gold 1,333Mhz
Graphics Card(s)
Palit HD4850 O/C Sonic 512Mb DDR3, Dual DViD's
Sound Card
Azalia to twin Samson 50w Studio Monitors
Monitor(s) Displays
Twin Dell (E-IPS) U2311H 23.6" Screens
Screen Resolution
1920 x 1080 @ 60Hz
Hard Drives
Crucial M4 SSD, archives on twin Western Digital Caviar Black WD2002FAEX, 2TB, 7200rpm HDD's, Samsung Ritemaster CD/DVD Burner...
PSU
OCZ 600w
Case
Lian-Li PC8 acoustifoamed' aluminium tower
Cooling
Scythe 140mm Zipang
Keyboard
Cherry PS/2 custom model
Mouse
Lenovo USB laser "Thinkpad" Mouse
Internet Speed
ADSL2+ @14Mbps downstream & Cat6 Gigabit Ethernet
Antivirus
NOD32
Browser
Opera
Other Info
Silicon Dust HD Homerun Dual FTA (Ethernet) TV Tuners, Dray Tek Vigor 2850Vn router and 8x HP Gigabit Switch. Lian-Li CR26 Card Reader, Canon MF4430 iSensys laser printer/scanner.
This stuff installs it'self .... you get it (if you're not properly secured) whether you want it or not! :eek:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
This stuff installs it'self .... you get it (if you're not properly secured) whether you want it or not! :eek:

How does it execute without user consent?
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
"They are spread using the same methods use to distribute other malware: for instance, a Trojan-Downloader can secretly download such programs, or vulnerabilities in compromised/ infected sites can be exploited to perform a drive-by download." Viruslist.com - Rogue antivirus: a growing problem
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
"They are spread using the same methods use to distribute other malware: for instance, a Trojan-Downloader can secretly download such programs, or vulnerabilities in compromised/ infected sites can be exploited to perform a drive-by download." Viruslist.com - Rogue antivirus: a growing problem

Wow. That's scary, to be sure! Do drive-by downloads execute the downloaded programs automatically?

So, for instance, does this mean that if you view a trusted website that is unwittingly hosted malvertizement (i.e. compromised banner-ad on New York Times website a few weeks ago) you're done for? Is it impossible to prevent this kind of attack now, even from sites you trust?
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
You want prevention before the fact .... You need a good Hosts file and and a program that prevents automatic Active X from downloading.
I use SpywareBlaster and SpywareGuard. Download and tutorials:
SpywareBlaster and SpywareGuard:
http://www.javacoolsoftware.com/products.html
Spyware Guard is a real-time malware scanner
SpywareBlaster tutorial:
http://www.bleepingcomputer.com/forums/Using_SpywareBlaster_to_protect_your_computer_from_Spyware_Hijackers_and_Malware-tut49.html
SpywareGuard tutorial:
http://www.bleepingcomputer.com/forums/Using_SpywareGuard_to_protect_your_computer_from_Spyware_and_Hijackers-tut50.html

You also need an active firewall program along with an updated antivirus and anti-spyware program.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Installs itself my@r$e... the sort of product being talked about is something like, say, 'Anti-virus 2009' which fools unsuspecting users into clicking on it and installing the file they download... these type of things are most definitely not 'driveby' malware... :zip:
 

My Computer

Computer Manufacturer/Model Number
Custom built machine
OS
W7 x64
CPU
Intel Q9300 2.5Ghz Quad LGA775 (Would like Q9650)
Motherboard
Gigabyte GA-EP45T-UD3R (F6 Bios)
Memory
4Gb OCZ Gold 1,333Mhz
Graphics Card(s)
Palit HD4850 O/C Sonic 512Mb DDR3, Dual DViD's
Sound Card
Azalia to twin Samson 50w Studio Monitors
Monitor(s) Displays
Twin Dell (E-IPS) U2311H 23.6" Screens
Screen Resolution
1920 x 1080 @ 60Hz
Hard Drives
Crucial M4 SSD, archives on twin Western Digital Caviar Black WD2002FAEX, 2TB, 7200rpm HDD's, Samsung Ritemaster CD/DVD Burner...
PSU
OCZ 600w
Case
Lian-Li PC8 acoustifoamed' aluminium tower
Cooling
Scythe 140mm Zipang
Keyboard
Cherry PS/2 custom model
Mouse
Lenovo USB laser "Thinkpad" Mouse
Internet Speed
ADSL2+ @14Mbps downstream & Cat6 Gigabit Ethernet
Antivirus
NOD32
Browser
Opera
Other Info
Silicon Dust HD Homerun Dual FTA (Ethernet) TV Tuners, Dray Tek Vigor 2850Vn router and 8x HP Gigabit Switch. Lian-Li CR26 Card Reader, Canon MF4430 iSensys laser printer/scanner.
Malicious code is inserted .... even if you click on the 'X' to close the pop-up window, a file has been dropped on the computer.
anti-virus rants: what is a drive-by download?

Virus Bulletin : Glossary - Drive-by download

One person mentioned to me that when a Rogue antivirus pop-up appeared on his machine, instead of closing it...he opened Task Manager and ended the process from there. We inspected his machine with a number of special malware tools and found that nothing malicious was installed. He was lucky!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Installs itself my@r$e... the sort of product being talked about is something like, say, 'Anti-virus 2009' which fools unsuspecting users into clicking on it and installing the file they download... these type of things are most definitely not 'driveby' malware... :zip:

Antivirus 2009 and MS AntiSpyware 2009 (msas2009.exe) - they work very similar.
Few months ago I uploaded on YT video with MSAS2009 infection on my VM, it is available here: http://www.youtube.com/watch?v=LRcxMhiHXGQ
As you can see it's step by step (DefenseWall HIPS, Online Armor HIPS and Firewall communicates) , how this rogue application infected systems, also please take it into account that this app do fake scan and shows fake "malware threats found" list - also you can clean/remove them but you have to paid and buy MSAS2009... lol. In fact this is very clever from malware writers side, and many people can be cheated by this type of fake security application.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 7 Home Premium x32 SP1
CPU
x2 2.6 GHz
Motherboard
Asus
Memory
A-Data 2GB DDR2-800
Graphics Card(s)
ATI X1250
Sound Card
SB 5.1 Live!
Hard Drives
WD and Seagate FAP
PSU
Tagan TG-480-U01
Keyboard
BTC 6300
Mouse
Logitech VX Nano
Antivirus
None
I ran into 3 of those last night while searching google. The very first link I clicked on popped up a fake antivirus scan and then tried to download a file to my computer. The problem is getting very bad!

I've come across many of these from legal sites. I emailed the sites with the link and told them to fix the links. Very nasty.
 

My Computer

Computer Manufacturer/Model Number
Built by Mark
OS
Windows 7 x64
CPU
Intel Core i7 930
Motherboard
Gigabyte GA-X58A-UD3R Bios F5
Memory
OCZ 6GBkit OCZ3G1600LV6GK 8-8-8-24-2T 1.65V
Graphics Card(s)
(2) HIS ATI Radeon HD 5770 CROSSFIRE (H577QT1GD)
Sound Card
On board Realtek HD
Monitor(s) Displays
Samsung SyncMaster 2343 22" Wide Screen
Screen Resolution
2048x1152
Hard Drives
Two Western Digital 320 Gig Blue series WDC WD3200AAKS-00L9A0
PSU
Corsiar 750 watts TX750W
Case
Antec NINE Hundred Two (air filters & adjustable fan speed)
Cooling
Cooler Master Hyper 212 Plus CPU cooler
Keyboard
Logitech
Mouse
Logitech MX310
Internet Speed
20 meg down/ 5 meg up
Other Info
Hewlett Packard Deskjet 932C printer
Epson 4990 Photo scanner
http://www.youtube.com/watch?v=LRcxMhiHXGQ[/URL]
As you can see it's step by step (DefenseWall HIPS, Online Armor HIPS and Firewall communicates) , how this rogue application infected systems, also please take it into account that this app do fake scan and shows fake "malware threats found" list - also you can clean/remove them but you have to paid and buy MSAS2009... lol. In fact this is very clever from malware writers side, and many people can be cheated by this type of fake security application.

This is a video by Creer ... the video has information and is not infected :cool:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top