« Watch out for those fake Rihanna nude pics
Nasty malware sample attempts to evade detection »

New rogue: Internet Antivirus Pro

May 11th, 2009

I was analyzing this rogue manually today and I wanted to show you how it hooks into your system.

To start off, a screen we are familiar with… Many untrue detections:

iapro1

This is a screen cap of one of our analysis tools:

iapro2

The rogue program creates five different run entries (which means it will try to run again each time you turn on your PC).

Notice how it uses legitimate Windows file names such as winlogon.exe or services.exe. This is to confuse users who will do Google searches and find out that winlogon.exe is actually a legitimate file. Well, in the world of computer viruses a name does not mean anything… I could name a file “sweetlittleflower” and yet it could be so nasty! ;-)

In our jargon, we identify binaries (files) with ’scientific’ methods. For example MD5 hashing, SHA1 etc… Not that they are 100% proof, but that’s how most AV products still work these days…

Jerome

    This entry was posted on Monday, May 11th, 2009 at 3:29 pm and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.