Pages

Showing posts with label Clean Malware. Show all posts
Showing posts with label Clean Malware. Show all posts

Thursday, February 11, 2010

Trojan.PWS.Onlinegames.KDCI - Online Games Malware

This is yet another variant of one of the most prolific online-games password stealer malware "families" out-there.

Upon execution, the first thing it does is to create autorun.inf files pointing to copies of itself, making sure it can survive after a system restart. These files will be located on root of the local drives of an affected system.

It creates another copy of itself into the temporary folder of the current user, where it also drops a new dll file which implements all the functionality required for stealing passwords related to MapleStory, The Lord Of The Rings Online, Knight Online, Dekaron or other games.

Friday, February 5, 2010

Trojan.Downloader.Bredolab.CJ - Virus Micr. Word Icon

This malware has a word document icon in oder to lure the user into opening it.

It copies itself in %Programs%\Startup\rarype32.exe in order to start along with Windows and removes traces of installation on the machine by deleting the original file which generated the infection.

Trojan.Downloader.Bredolab.CZ has 2 components:
- packed main executable
- downloader (which is never written on disk directly but is injected into other processes)

The trojan creates a custom unique mutex in order to check if the system is already infected. Also it inject itself into a running version of "explorer.exe"

Tuesday, February 2, 2010

Trojan.FakeAV.XP - Fake Antivirus Malware

The user receives messages of false infection on his computer in order to make him activate (buy) the fake antivirus product. The rogue antivirus resembles the program suite from the operating system and on the installation of the malware the user can notice the following image :


Also the malware creates the following file %CommonAppData%\[RandomString]\[RandomString].exe. Another noticeable sign of infection is the folder %AppData%\Enterprise Suite.

* A typical path for %CommonAppData% is C:\Documents and Settings\All Users\Application Data.

* A typical path for %AppData% is C:\Documents and Settings\[UserName]\Application Data.

Monday, February 1, 2010

Worm.Zimuse.A - WinZip icon Malware

SYMPTOMS:
Presence of the following files
  * %system32%\drivers\mstart.sys
  * %system32%\drivers\mseu.sys

TECHNICAL DESCRIPTION:
 The malware comes as an application with a WinZip icon in order to trick the user into running it. To look even more as a a self-extracting archive it displays a dialog box asking for a password in order to successfully unzip the package contents.

Friday, December 4, 2009

Autorun-Based Malware Tops BitDefender’s November Top Ten Threat Report

BUCHAREST, Romania – December 1, 2009 – BitDefender’s Top Ten Threat Report for November is topped by Trojan.AutorunInf.Gen. Trojan.AutorunInf.Gen, which came in second place on October’s list, is a generic family of malware abusing the Autorun feature in Microsoft Windows operating systems. By default, every removable storage device features an autorun.ini script that instructs the computer which file to execute when the medium is plugged in. Malware authors frequently tamper with the file to make it launch miscellaneous malicious applications.

Trojan.Clicker.CM moves down a spot, ranking second with nearly eight percent of total infections. Trojan.Clicker.CM is found on websites hosting illegal applications such as cracks, keygens and serial numbers for popular commercial software applications. Clicker.CM is used to force advertisements inside a user’s browser in order to boost advertisement revenue.

Trojan.Vb.AQT - Malware Type

Name alias Trojan.Win32.VB.aqt, Trojan.Recycle, W32.Fakerecy. Presence of this malware may be indicated by :
* a "Recycled" folder on each drive, which has the icon of the Recycle Bin

* presence of a file "autorun.inf" in the drive root, containing:
[autorun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0)

Upon execution malware creates on all fixed and removable drives:
[DRIVE]:\autorun.inf
[DRIVE]:\Recycled\desktop.ini
[DRIVE]:\Recycled\INFO2,
, which are used to execute the malware when the drive is accessed.

Tuesday, November 3, 2009

WORMS

Worms are similar to viruses in that they re self replicating. They reproduce themselves across networks without human assistance, such as e-mail sending. A worm, though, doesn't need another executable program to be distributed.

Worms usually affect networks more than individual computers on the network. Their selfreplicating behavior can overload network resources, causing slowdowns in data
transmission by consuming massive bandwidth normally used to forward normal traffic.
Network systems that route Internet traffic are just specialized computer hardware and software. They, too, can be affected by malware.

Monday, November 2, 2009

Trojan.Downloader.Bredolab.U - Malware

This malware is known for downloading rogue antiviruses (e.g. PC Antispyware 2010) : software products which once installed will generate alerts of fake infections and urge the user to fix those issues. The user is informed that in order to clean his computer of the threats, he needs to buy a license of that specific AV. In reality the product even after being licensed/registered will not delete any file or otherwise fix any of the detected issues.

SYMPTOMS:
The following symptoms are indicators of infection:
* unknown processes in task manager
* unrequested internet connections
* periodic messages the warn the user that "Windows has detected spyware infection"