Nume: TR/FakeAV.HM Descoperit pe data de: 06/08/2010 Tip: Troian ITW: Da Numar infectii raportate: Scazut spre mediu Potential de raspandire: Mediu Potential de distrugere: Mediu Fisier static: Da Marime: 878.592 Bytes MD5: b755deedb98872d8e255ae46d7f70289 Versiune IVDF: 7.10.10.99 - Freitag, 6. August 2010
General Metoda de raspandire: • Nu are rutina proprie de raspandire Alias: • Avast: Win32:Genome-IO • Microsoft: Trojan:Win32/FakeScanti • Eset: Win32/Adware.PCProtector.D • GData: Win32:Genome-IO • DrWeb: Trojan.Fakealert.18615 Sistem de operare: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows Server 2008 • Windows 7 Efecte secundare: • Creeaza fisiere malware • Raporteaza probleme de sistem sau infectii malware inexistente si se ofera sa le repare daca utilizatorul cumpara aplicatia. • Modificari in registri Imediat dupa lansarea in executie, pe ecran este afisat: Fisiere Se copiaza in urmatoarea locatie: • %PROGRAM FILES%\Wireshark Antivirus\Wireshark Antivirus.exe Sunt create fisierele: – %HOME%\Start Menu\Programs\WireShark Antivirus\Wireshark Antivirus.lnk – %HOME%\Desktop\Wireshark Antivirus.lnk – %PROGRAM FILES%\wp4.dat – %PROGRAM FILES%\svchost.exe Fisierul este executat dupa ce a fost creat. Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/Agent.25600.AA – %PROGRAM FILES%\adc_w32.dll Fisierul este executat dupa ce a fost creat. Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/BHO.CK – %PROGRAM FILES%\alggui.exe Fisierul este executat dupa ce a fost creat. Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: TR/Agent.42496.AA – %PROGRAM FILES%\nuar.old – %TEMPDIR%\win19.tmp – %PROGRAM FILES%\wp3.dat – %PROGRAM FILES%\scdata\dbsinit.exe Fisierul este executat dupa ce a fost creat. Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: 5318 Registrii sistemului Urmatoarele chei sunt adaugate in registri pentru a incarca serviciile la repornirea sistemului: – [HKLM\SYSTEM\CurrentControlSet\Services\AdbUpd] • "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"="%PROGRAM FILES%\svchost.exe" "DisplayName"="Adobe Update Service" "ObjectName"="LocalSystem" – [HKLM\SYSTEM\CurrentControlSet\Services\AdbUpd\Security] • "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 – [HKLM\SYSTEM\CurrentControlSet\Services\AdbUpd\Enum] • "0"="Root\\LEGACY_ADBUPD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 Inregistreaza un browser helper object (BHO) prin adaugarea urmatoarei chei in registri: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}] Urmatoarele chei sunt adaugate in registrii sistemului: – [HKCU\Software\Wireshark Antivirus] – [HKCU\Software\Wireshark Antivirus\Wireshark Antivirus] – [HKCU\Software\Wireshark Antivirus\Wireshark Antivirus\setdata] – [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD] • "NextInstance"=dword:00000001 – [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD\0000] • "Service"="AdbUpd" • "Legacy"=dword:00000001 • "ConfigFlags"=dword:00000000 • "Class"="LegacyDriver" • "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}" • "DeviceDesc"="Adobe Update Service" – [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD\0000\ Control] • "*NewlyCreated*"=dword:00000000 • "ActiveService"="AdbUpd" – [HKCR\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}] • @="ADC PlugIn" – [HKCR\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32] • @="%PROGRAM FILES%\adc_w32.dll" • "ThreadingModel"="Apartment" Injectarea codului malware in alte procese – Se injecteaza intr-un proces. Numele procesului: • %PROGRAM FILES%\svchost.exe In cazul esecului operatiunii, malware-ul se inchide. In caz de succes, malware-ul afiseaza urmatoarele:
Die Beschreibung wurde erstellt von Patrick Schoenherr am Freitag, 6. August 2010 Die Beschreibung wurde geändert von Patrick Schoenherr am Freitag, 6. August 2010
zurück
.
.
.
.