Friday, March 27, 2009

InternetAntivirusPro Spyware spread new variants

InternetAntivirusPro Spyware spread new variants

Some new websites appear to distribute a new variant of the fake antispyware InternetAntivirusPro
Detected as WinWebSecurity or FakeSpyGuard. 2 or 3 new sites are registered every day.

READ THIS page if you need more information

Site screenshot retreived from this page (same domains)
A list can be found here

bestscan5.com [March 31]
fuse4scan.com [March 27]
gotimescan.com [march 28]
list4scan.com [march 28]
logscan6.com [March 26]
mainscan6.com [March 27]
scan4fuse.com [March 28]
scan4open.com [March 28]
scan4plus.info [March 29]
slot4scan.com [March 28]
new4scan.info [March 30]
scan4live.info [March 30]
scan4pro.info [March 31]

April new:

best4scan.info [April 1]
best6scan.info [April 2]
pro4scan.info [April 1]
scanline6.com [April 2]
scan6log.com [April 1]
scan6main.com [April 1]
scan6now.com [April 1]
zpmuwbtqqwkw.net [April 1]

-----------
Other ACTIVE:

Registrar NETEARTH ONE, INC. DBA NETEARTH
Domain: 5scanav.com, scan5av.com
Registration Service Provided By: SELLOUT.NAME
----------
Created on January 14 2009

Registrar: REGTIME LTD
Domain: scan5plus.com
DNS Servers: NS1.SCAN5PLUS.COM NS2.SCAN5PLUS.COM
----------
Created on March 16 2009

Registrar: UK2 GROUP LTD.
Domain: logscan6.com
DNS Servers: NS1.SITELUTIONS.COM NS2.SITELUTIONS.COM
Registration Service Provided By: SELLOUT.NAME
-------------
Created on March 23 2009:

Registrar: UK2 GROUP LTD.
Domain: scan4way.com
DNS Servers used are NS1.DNSEXIT.COM - NS2.DNSEXIT.COM
Registration Service Provided By: SELLOUT.NAME
-------------

Fake Trojan-IM.Win32.Faker.a Alert - Internet Antivirus Pro Warning:

Trojan-IM.Win32.Faker.a
Virus.Win32.Faker.a
Trojan.PSW.BAT.Cunter



scan4lite.com Fake message: Trojan-IM.Win32.Faker.a

scan4lite.com Fake message: Trojan-IM.Win32.Faker.a

scan4lite.com Virus

Fake messages:

scan4lite.com Fake Security Warning Message

scan4lite.com Fake Security Warning Message

Fake Windows Security Alert:

Admess.Trojan
zserv.Transponder.Trojan
Wstart.TrojanDownloader
Email-Worm.Win32.Net
Email-Worm.Win32.Myd
Trojan-Downloader.Win

Serious security and privacy threats found on your computer.

It may damage your files or steal your personal and financial information.

Click "OK" to start downloading CRITICAL security software update.

Other template:

Fake Admess.Trojan - WinWebSecurity
Fake Scanner - WinWebSecurity

Fake Scanner:




Fake messages:

Fake Scanner - SystemSecurity message - WinWebSecurity Fake Scanner - SystemSecurity message - WinWebSecurity

Analysis of logscan6.com, mainscan6.com, logscan6.com:


 Site URLs:hxxp://www.mainscan6.com/22/?uid=keyin 
  hxxp://www.mainscan6.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD5a63bd2a45057c5f589d8e75b429b02a8 
    
 ThreatExpert:Report for InternetAntivirusPro - Rootkit.Win32.TDSS 
 Anubis:Report 
 VirusTotal:Report 
    
 First received03.27.2009 06:42:43 (CET) 
 Results5/39 (12.50%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQIkraus 
  Trojan.Dldr.LooksLike.FraudLoadMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 
  Trojan.Win32.Tdss.qxr (v) Other ScannerSunbelt 
  Trojan-Downloader.Win32.Renos.AQ
(Sig-Id:380322)
Ikarus Virus Scanner 

    
 Site URLs:hxxp://logscan6.com/22/?uid=keyin 
  hxxp://logscan6.com/download/install.php 
    
 File info:install.exe 
    
 File size40960 bytes 
 MD5805d2e58e045471056b0bb7376b5b276 
    
 Anubis:Anubis Report 
 ThreatExpert:ThreatExpert Report 
 VirusTotal:VirusTotal Report 
    
 First received03.26.2009 22:50:25 (CET) 
 Results6/39 (15.39%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Generic!ArtemisMcAfee+Artemis 
  Trojan.Dldr.LooksLike.FraudLoadMcAfee-GW-Edition 
  Trojan:Win32/InternetAntivirusMicrosoft 

    
 Site URLs:hxxp://fuse4scan.com/22/?uid=keyin 
  hxxp://fuse4scan.com/download/install.php 
    
 File info:install.exe 
    
 File size40960 bytes 
 MD5bcfede07fc9834bab8c114af357bd559 
    
 Anubis:Anubis Report 
 VirusTotal:VirusTotal Report 
    
 First received03.27.2009 02:34:00 (CET) 
 Results5/40 (15.39%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Generic!ArtemisMcAfee+Artemis 
  Trojan:Win32/InternetAntivirusMicrosoft 

    
 Site URLs:hxxp://list4scan.com/22/?uid=keyin 
  hxxp://list4scan.com/download/install.php 
    
 File info:RegCureSetup_RW.exe 
    
 File size40960 bytes 
 MD5529b7b5d0025995803ce374353ae197d 
    
 Anubis:Anubis Report 
 ThreatExpert:ThreatExpert Report 
 VirusTotal:VirusTotal Report 
    
 First received03.27.2009 23:31:23 (CET) 
 Results6/39 (15.38%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  FakeAlert.IKAVG 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan.LooksLike.PCK.TdssMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 

      
 Site URLs: hxxp://scan4fuse.com/22/?uid=keyin 
   hxxp://scan4fuse.com/download/install.php 
  hxxp://slot4scan.com/22/?uid=keyin 
  hxxp://slot4scan.com/download/install.php 
     
 File info: install.exe 
     
 File size 41472 bytes 
 MD5 705bc1d5c3467ce797eb62b92334279e 
     
 Anubis: Anubis Report 
 ThreatExpert: ThreatExpert Report 
 VirusTotal: VirusTotal Report 
     
 First received 03.28.2009 00:26:36 (CET) 
 Results 7/39 (18.92%) 
     
 Alias: Trojan-Downloader.Win32.Renos.AQ!IK a-squared 
  HEUR/CryptedAntivir 
  FakeAlert.IKAVG 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan.LooksLike.PCK.TdssMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 


    
 Site URLs:hxxp://scan4open.com/22/?uid=keyin 
  hxxp://scan4open.com/download/install.php 
    
 File info:install.exe 
    
 File size40960 bytes 
 MD52ecba36cd9af4a8c47b2f0423db7c8d6 
    
 Anubis:Anubis Report 
 ThreatExpert:ThreatExpert Report 
 VirusTotal:VirusTotal Report 
    
 First received03.29.2009 04:29:12 (CET) 
 Results6/39 (15.39%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  FakeAlert.IKAVG 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan.LooksLike.PCK.TdssMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 

    
 Site URLs:hxxp://scan4plus.info/?uid=12404 
  hxxp://scan4plus.info/download/install.php 
    
 File info:install.exe 
    
 File size40960 bytes 
 MD50471c7f12fa9074bd14a5a4b1393e670 
    
 Anubis:Anubis Report (Ikarus: Trojan.Win32.FakeSpyguard (Sig-Id:469235)) 
 ThreatExpert:ThreatExpert Report 
 VirusTotal:VirusTotal Report 
    
 First received03.29.2009 23:44:36 (CET) 
 Results5/38 (13.13%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan.LooksLike.PCK.TdssMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 


Result when running:
 


HTTP Request: 66.197.154.198:80 - [in6ik.com]
Request: GET /download/InternetAntivirusPro.exe

File size: 1939663 bytes
MD5: d0e1c85deed607184fb5b3eb3fe5bf1a

ThreatExpert
VirusTotal Report

***************

HTTP Request: 78.159.101.27:80 - [in4iz.com]
Request: GET /download/InternetAntivirusPro.exe

File size: 2160737 bytes
MD5: 1e1c910953bf69e6dc02e1ad956b99c9

Only Sophos detect this new variant!

ThreatExpert
VirusTotal Report

****************

HTTP Request: 62.211.68.12:80 - [xoomer.virgilio.it]
Request: GET /tatatro/InternetAntivirusPro.exe

File size: 2160769 bytes
MD5: 4ca7119843d27c1bd3ad327b1dbb93cb

ThreatExpert
VirusTotal Report

    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Win32.MalFakeAV.meSafe 
  FakeAlert-ABMcAfee 
  FakeAlert-ABMcAfee+Artemis 
  Mal/FakeAV-MSophos 
  Adware.IAPro.R.1939663ViRobot 


Some removal information can be found below

- Kill processes: *random file name*.exe, SystemSecurity.exe, av.exe, InternetAntivirusPro.exe

- Delete registry keys:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\Uninstall\SystemSecurity2009
  • HKEY_LOCAL_MACHINE\SOFTWARE\ [random file.exe*]
* random filename/random name: 8 digit like 00309781.exe

- Delete registry values:
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    {random key name *} = ""

    random file name * = "%CommonAppData%\*random filename*\*random filename*.exe"

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    Uninstall\SystemSecurity2009]

    DisplayName = "System Security 2009"

    ShortcutPath = "%Programs%\System Security\
    System Security 2009 Support.lnk"

    UninstallString = "%Programs%\System Security\System Security 2009 Support.lnk"

    DisplayIcon = "%CommonAppData%\*random file name*\*random filename.exe*,0"

  • [HKEY_LOCAL_MACHINE\SOFTWARE\00309781]

    pc*random 8-digit*ins = 0x00000001
* random key name:
32 alpha-numeric value like 90BF8224-CD63-4081-A4C7-EF9A2CF6596F

* random 8-digit:
8 digit value like pc00309781ins "The same number of the executable"

- Delete files and folders:

  • ► %CommonAppData%\*random name*\pc*random 8-digit*ins
  • ► %CommonAppData%\*random name*
    ► %DesktopDir%\System Security 2009.lnk
    ► %Programs%\System Security\
  • ► %Programs%\System Security\System Security 2009 Support.lnk
    ► %Programs%\System Security\System Security 2009 Support.lnk
    ► %Programs%\System Security\System Security 2009.lnk