Sunday, March 22, 2009

SystemSecurity2009 spread new variants - Fake Admess.Trojan

SystemSecurity2009 WinWebSecurity Spyware spread new variants

A few days ago, the famous WinWebSecurity (SystemSecurity2009) appear to
spread new variants. This rogue application install Internet Antivirus Pro a fake antispyware.

READ THIS page if you need more information

New sites on March 27

Site screenshot:

(redirectors: goscanplan.com)

fusescan4.com [March 24]
linescan6.com [March 25]
scan4any.com
scan4lite.com
scan4true.com
slotscan4.com [March 25]
wayscan4.com [March 24]

Fake Trojan-IM.Win32.Faker.a Alert - Internet Antivirus Pro Warning:

Trojan-IM.Win32.Faker.a
Virus.Win32.Faker.a
Trojan.PSW.BAT.Cunter



scan4lite.com Fake message: Trojan-IM.Win32.Faker.a

scan4lite.com Fake message: Trojan-IM.Win32.Faker.a

scan4lite.com Virus

Fake messages:

scan4lite.com Fake Security Warning Message

scan4lite.com Fake Security Warning Message

Serious security and privacy threats found on your computer.

It may damage your files or steal your personal and financial information.

Click "OK" to start downloading CRITICAL security software update.

Other template:

greatvirusscan.com (March 1)
internetsafetyexamine.com (March 26)
internetsafetyskim.com (March 23)
myinternetexamine.com (March 26)
onlinescandetect.com (March 27)
scanalertspage.com
scanbaseonline.com (April 1)
securityexamine.com (March 30)
protectionskim.com
protectionexamine.com (March 26)
runpcscannow.com (March 30)
safetyscansite.com (March 23)
securityscanguide.com (April 1)
thestabilityinternet.com (March 23)
yourstabilitysystem.com (March 23)
yourinternetexamine.com (March 26)
youronlinestability.com (March 26)
wwwprotectionreads.com (March 25)
wwwprotectionread.com (March 21)
webnetsafety.com

Fake Admess.Trojan - WinWebSecurity
Fake Scanner - WinWebSecurity

Fake Scanner:

http://safetyscanworld.com/scan.php?affid=01990
http://scanalertspage.com/scan.php?affid=01990
http://thestabilityinternet.com/scan.php
http://yourstabilitysystem.com/scan.php?affid=08055
http://webnetsafety.com/scan.php?affid=01990
http://wwwsecurityread.com/scan.php?affid=01990
Redirector for wwwsecurityread.com (onlinedetect.com) Analysis




Same as stabilityinetscan.com here

Fake messages:

Fake Scanner - SystemSecurity message - WinWebSecurity Fake Scanner - SystemSecurity message - WinWebSecurity

Warning!!! Your computer contains various signs of viruses and malware
programs presence.
Your system requires immediate anti viruses check!
System Security will perform a quick and free scanning of your PC
for viruses and malicious programs.

Your computer remains infected by viruses!
They can cause data loss and file damages and need to be
cured as soon as possible.
Return to System Security and download it secure to your PC

This program is potentially dangerous for your system.
Trojan-Downloader stealing passwords, credit cards and
other personal information from your computer.

You need to remove this threat as soon as possible!

Email-Worm.Win32.Net
Email-Worm.Win32.Myd
Trojan-Downloader.Win

Fake Windows Security Alert:

Admess.Trojan
zserv.Transponder.Trojan
Wstart.TrojanDownloader

Fake Windows Security Alert - Fake Admess.Trojan

Other sites:

getscanonline.com - ThreatExpert
onlinesafetyscansite.com - ThreatExpert
onlinescandetect.com - ThreatExpert
protectionexamine.com - ThreatExpert
protectionskim.com - ThreatExpert
runpcscannow.com - ThreatExpert
safetyscansite.com - TreathExpert
safetyscanworld.com - ThreatExpert
scanalertspage.com - ThreatExpert
scanbaseonline.com - ThreatExpert
securityexamine.com - ThreatExpert
securityscanguide.com - ThreatExpert
securityscansite.com - ThreatExpert
thestabilityinternet.com - ThreatExpert
youronlinestability.com - ThreatExpert
yourstabilitysystem.com - ThreatExpert
wwwprotectionread.com - ThreatExpert
wwwprotectionreads.com - ThreatExpert
wwwsecurityread.com - ThreatExpert
webnetsafety.com - ThreatExpert
xprotect.us - ThreatExpert

Analysis of scan4lite.com, scan4any.com, scan4true.com, openscan4.com:


 Site URLs:hxxp://www.scan4lite.com/22/?uid=keyin 
  hxxp://scan4lite.com/download/install.php 
  hxxp://www.scan4any.com/22/?uid=keyin 
  hxxp://scan4any.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD5b5e3df07d5963928552015bdf202465f 
    
 ThreatExpert:Report for InternetAntivirusPro 
 Anubis:Report 
 VirusTotal:Report 
    
 First received03.24.2009 06:14:11 (CET) 
 Results7/39 (17.95%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Gen:Trojan.Heur.TDSS.2040BFAFAFBitdefender 
  Suspicious fileeSafe 
  Gen:Trojan.Heur.TDSS.2040BFAFAF GData 
  Trojan-Downloader.Win32.Renos.AQIkraus 
  VirTool:Win32/Obfuscator.DQMicrosoft 
  Trojan.Win32.Tdss.qxr (v)Sunbelt 
  Trojan-Downloader.Win32.Renos.AQ
(Sig-Id:380322)
Ikarus Virus Scanner 

    
 Site URLs:hxxp://scan4true.com/22/?uid=keyin 
  hxxp://scan4true.com/download/install.php 
  hxxp://openscan4.com/22/?uid=keyin 
  hxxp://openscan4.com/download/install.php 
    
 Redirection:Found on goscanway.com for scan4true.com [Analysis] 
    
 File info:install.exe 
    
 File size40960 bytes 
 MD5ae744b601d2889e55fa507c297a47b16 
    
 ThreatExpert:Report for Rootkit.Win32.TDSS 
 ThreatExpert:ThreatExpert Report for install.exe [openscan4.com] 
 Anubis:Anubis Report for install.exe [openscan4.com] 
 VirusTotal:VirusTotal Report for install.exe [openscan4.com] 
    
 First received03.25.2009 05:51:39 (CET) 
 Results6/40 (15.00%) 
    
 Alias:Trojan.Win32.FakeSpyguard!IKa-squared 
  Suspicious fileeSafe 
  Packed.Win32.Tdss.fF-Secure 
  Trojan.Win32.FakeSpyguard Ikarus 
  Packed.Win32.Tdss.fKaspersky 
  Trojan:Win32/InternetAntivirusMicrosoft 

       
 Site URLs:hxxp://fusescan4.com/22/?uid=keyin 
  hxxp://fusescan4.com/download/install.php 
  http://scanfuse4.com/22/?uid=keyin 
  http://scanfuse4.com/download/install.php 
  hxxp://scanopen4.com/22/?uid=keyin 
  hxxp://scanopen4.com/download/install.php 
  hxxp://wayscan4.com/22/?uid=keyin 
  hxxp://wayscan4.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD5c2863c37df25478a66986734e08143ea 
    
 Anubis:Anubis Report 
 VirusTotal:VirusTotal Report 
    
 First received03.25.2009 15:08:26 (CET) 
 Results4/40 (10.00%) 
     
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan:Win32/InternetAntivirusMicrosoft 
     
 VirusTotal: VirusTotal Second Report 
     
 Reanalysed 03.25.2009 23:19:58 (CET) 
   10/40 (25.00%) 
     
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  FakeAlert.INAVG 
  Trojan.DownLoad.26790 DrWeb 
  Suspicious FileeSafe 
  Trojan-Downloader.Win32.Renos Ikarus 
  Trojan-Downloader.Win32.FraudLoad.dyiKaspersky 
  Generic!ArtemisMcAfee+Artemis 
  Trojan.LooksLike.PCK.TdssMcAfee-GW-Edition 
  Trojan:Win32/InternetAntivirusMicrosoft 
  Mal/TDSSPack-ASophos 

    
 Site URLs:hxxp://linescan6.com/22/?uid=keyin 
  hxxp://linescan6.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD501c7559c1ffb94c7f48c3c7ceaee1742 
    
 VirusTotal:VirusTotal Report 
    
 First received03.25.2009 19:23:37 (CET) 
 Results4/40 (10.00%) 
    
 Alias:SecurityRisk.Downldr[Symantec] 
  Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan:Win32/InternetAntivirusMicrosoft 

    
 Site URLs:hxxp://slotscan4.com/22/?uid=keyin 
  hxxp://slotscan4.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD50f4a296648be81e091348115ef03620a 
    
 VirusTotal:VirusTotal Report 
    
 First received03.25.2009 19:25:43 (CET) 
 Results4/40 (10.00%) 
    
 Alias:SecurityRisk.Downldr[Symantec] 
  Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan:Win32/InternetAntivirusMicrosoft 

    
 Site URLs:hxxp://home6scan.com/22/?uid=keyin 
  hxxp://home6scan.com/download/install.php 
    
    
    
 File info:RegCureSetup_RW.exe 
 File info:install.exe 
    
 File size40960 bytes 
 MD5805d2e58e045471056b0bb7376b5b276 
    
 Anubis:Anubis Report 
 VirusTotal:VirusTotal Report 1 
 VirusTotal:VirusTotal Report 2 
    
 First received03.26.2009 22:50:25 (CET) 
 Results6/39 (15.39%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Generic!ArtemisMcAfee+Artemis 
  Trojan.Dldr.LooksLike.FraudLoadMcAfee-GW-Edition 
  Trojan:Win32/InternetAntivirusMicrosoft 

    
 Site URLs:hxxp://scanlist4.com/22/?uid=keyin 
  hxxp://scanlist4.com/download/install.php 
    
 File info:install.exe 
    
 File size40448 bytes 
 MD5bcfede07fc9834bab8c114af357bd559 
    
 Anubis:Anubis Report 
 VirusTotal:VirusTotal Report 
    
 First received03.26.2009 22:50:25 (CET) 
 Results6/39 (15.39%) 
    
 Alias:Trojan-Downloader.Win32.Renos.AQ!IKa-squared 
  Suspicious fileeSafe 
  Trojan-Downloader.Win32.Renos.AQ Ikarus 
  Trojan.Dldr.LooksLike.FraudLoadMcAfee-GW-Edition 
  VirTool:Win32/Obfuscator.DQMicrosoft 

Result when running:
 


HTTP Request: 78.159.101.27:80- [in4ik.com]
Request: GET /download/InternetAntivirusPro.exe

Analysis of yourstabilitysystem.com, protectionexamine.com:


 Site URLs:yourstabilitysystem.com/download.php?affid=00000 
  yourstabilitysystem.com/load.swf?&p=0&t=_self&u=
download.php?affid=..
 
    
    
 File info:install.exe 
    
 File size106536 bytes 
 MD53866b483ba93922bd6c07327c2c93b74 
    
    
 ThreatExpertOther source 
 ThreatExpert:Report 
 Anubis:Report 
 VirusTotal:Report 
 Prevx:Report 
    
 First received03.24.2009 10:11:44 (CET) 
 ResultsResult: 10/39 (25.64%) 
    
 Alias:Trojan-Dropper.Agent!IK a-squared 
  FakeAler.IIAVG 
  Suspicious fileeSafe 
  Rogue:W32/Winwebsec.C F-Secure 
  PECompactKaspersky 
  Program:Win32/WinwebsecMicrosoft 
  Medium Risk MalwarePrevx 
  Trojan.Win32.FakeAV.ikRising 
  Mal/FakeAV-ADSophos 
  Trojan-Dropper.Agent (Sig-Id:315644)Ikarus Virus Scanner 

    
 Site URLs:hxxp://protectionexamine.com 
  hxxp://protectionexamine.com/download.php 
    
 File info:install.exe 
    
 File size121894 bytes 
 MD505a446ef1a99d872a7cae5061ab8c6bc 
    
 VirusTotal:VirusTotal Report 
 Anubis:Anubis Report 
 ThreatExpert:ThreatExpert Report 
    
 First received03.26.2009 03:53:02 (CET) 
 Results17/40 (42.5%) 
    
 Alias:ADSPY/AdSpy.GenAntivir 
  FakeAlert.IIAVG 
  (Suspicious) - DNAScanCAT-QuickHeal 
  Trojan.Fakealert.4123 DrWeb 
  Suspicious FileeSafe 
  PECompactF-Secure 
  PECompactKaspersky 
  Ad-Spyware.AdSpy.GenMcAfee-GW-Edition 
  Program:Win32/WinwebsecMicrosoft 
  Win32/Adware.SystemSecurityNOD32 
  Adware/SystemSecurityPanda 
  Medium Risk MalwarePrevx1 
  Trojan.Win32.FakeAV.ikRising 
  Mal/FakeAV-ADSophos 
  Downloader.MisleadAppSymantec 
  PAK_Generic.001Trend Micro 
  Hoax.Win32.SystemSecurityVBA32 
     
  Prevx: 02419843.EXE  
     

    
 Site URLs:hxxp://myinternetexamine.com 
  hxxp://yourinternetexamine.com/installer_1.exe 
    
 File info:installer_1.exe 
    
 File size546816 bytes 
 MD5916e0f7aef7f1ea6308fa886d41ed750 
    
 VirusTotal:VirusTotal Report 
 ThreatExpert:ThreatExpert Report 
    
 First received03.25.2009 17:40:43 (CET) 
 Results15/40 (37.50%) 
    
 Alias:Trojan.Renos  

Result when running:
 
Same image below

HTTP Request: 209.44.126.14:80 - [yourstabilitysystem.com]
Request: GET /install/ws.zip

 File info:ws.zip 
    
 File size486912 bytes 
 MD598c4ef71de9efbe243e8456a9896525a 
    
    
 VirusTotal:Report 
    
 First received03.24.2009 10:35:59 (CET) 
 ResultsResult: 9/39 (25%) 
    
 Alias:FakeAlert.II [AVG] 
  Suspicious File [eSafe] 
  Program:Win32/Winwebsec [Microsoft] 

Analysis after decompression of ws.zip

 File info:av.exe  
  av.glu (config file) 
    
 File size486912 bytes 
 MD598c4ef71de9efbe243e8456a9896525a 
    
    
 VirusTotal:Report 
    
 First received03.23.2009 16:30:10 (CET) 
 ResultsResult: 5/39 (12.82%) 
    
 Alias:FakeAlert.II [AVG] 
  Suspicious File [eSafe] 
  Program:Win32/Winwebsec [Microsoft] 

Result for protectionexamine.com

Same image below

HTTP Request: 94.247.3.3:80 - [protectionexamine.com] ZlKon
Request: GET /install/ws.zip

 File info:ws.zip 
    
 File size393512 bytes 
 MD5130bd371cebd991641496329afc8aa60 
    
    
 VirusTotal:Report 
    
 First received 03.26.2009 04:10:33 (CET) 
 ResultsResult: 13/40 (32.5%) 
    
 Alias:Generic.Win32.Malware!IK [a-squared] 
  TR/Fake.SysSec [Antivir] 
  FakeAlert.II [AVG] 
  Suspicious File [eSafe] 
  PECompact [F-Secure] 
  Generic.Win32.Malware [Ikarus] 
  PECompact [Kaspersky] 
  Generic!Artemis [McAfee+Artemis] 
  Trojan.Fake.SysSec [McAfee-GW-Edition] 
  Program:Win32/Winwebsec [Microsoft] 
  Adware/SystemSecurity [Panda] 
  Trojan.Fakeavalert [Symantec] 
  Hoax.Win32.SystemSecurity [VBA32] 

Analysis after decompression of ws.zip

 File info:av.exe  
  av.glu (config file) 
    
 File size522240 bytes 
 MD5565d30af7e1a42cdb859ae60c290b064 
    
    
 VirusTotal:Report 
    
 First received03.25.2009 17:06:13 (CET) 
 ResultsResult: 7/39 (17.95%) 
    
 Alias:TR/Fake.SysSec [Antivir] 
  FakeAlert.II [AVG] 
  Suspicious File [eSafe] 
  PECompact [F-Secure] 
  PECompact [Kaspersky] 
  Trojan.Fake.SysSec [McAfee-GW-Edition] 
  Program:Win32/Winwebsec [Microsoft] 


Analysis of protectionskim.com:


 Site URLs:protectionskim.com/download.php?affid=00000 
    
    
 File info:install.exe 
    
 File size94127bytes 
 MD5cede29db9fdae662c59d6a01da7a85f3 
    
    
 ThreatExpertOther source 
 ThreatExpert:Report 
 Anubis:Report 
 VirusTotal:Report 
    
 First received03.21.2009 16:00:04 (CET) 
 Results12/39 (66.67%) 
    
 Alias:W32/FakeAV.8074!tr 
  Trojan-Downloader.Win32.FraudLoad.vmtk 
  SHeur2.WXJ 
  TR/Crypt.XPACK.Gen 
  Sus/FakeAV-A 
  Trojan-Dropper.Agent (Sig-Id:315644) [Ikarus Virus Scanner] 

Result when running:
 SystemSecurity WinWebSecurity
SystemSecurity WinWebSecurity

HTTP Request: 209.44.126.22:80 - [protectionskim.com]
Request: GET /install/ws.zip


 File info:av.exe  
    av.glu (config file)  
    
 File size 315392 bytes 
 MD5f54d79a2fb5e0b21a4caf6cbe165b839 
    
    
  ThreatExpert Other source - av.exe  
 VirusTotal:Report 
    
 First received03.22.2009 00:02:45 (CET) 
 Results Result: 2/39 (41.03%) 
    
 Alias: (Suspicious) - DNAScan [CAT-QuickHeal] 
  Suspicious File [eSafe] 
  Win32.FraudLoad.vmsd [Kaspersky] 


Analysis of scanalertspage.com:


 Site URLs:scanalertspage.com/download.php?affid=00000 
    
    
 File info:install.exe 
    
 File size94767 bytes 
 MD55da9957ea446494a800fa772c1cac5ba 
    
    
 ThreatExpertOther source 
 ThreatExpert:Report 
 Anubis:Report 
 VirusTotal:Report 
    
 First received03.22.2009 10:25:32 (CET) 
 Results9/39 (23.08%) 
    
 Alias:SHeur2.WXJ 
  Trojan-Downloader.Win32.FraudLoad.dxh 
  Sus/FakeAV-A 
  Trojan-Dropper.Agent (Sig-Id:315644) [Ikarus Virus Scanner] 

Result when running:
 SystemSecurity WinWebSecurity
SystemSecurity WinWebSecurity

HTTP Request: 209.44.126.14:80 - [scanalertspage.com]
Request: GET /install/ws.zip


 File info:av.exe  
  av.glu (config file) 
    
 File size 315392 bytes 
 MD5f54d79a2fb5e0b21a4caf6cbe165b839 
    
    
 VirusTotal:Report 
    
 First received03.22.2009 00:02:45 (CET) 
 ResultsResult: 3/39 (41.03%) 
    
 Alias:(Suspicious) - DNAScan [CAT-QuickHeal] 
  Suspicious File [eSafe] 
  Win32.FraudLoad.vmsd [Kaspersky] 


Analysis of webnetsafety.com:


 Site URLs:webnetsafety.com/download.php?affid=00000 
    
    
 File info:install.exe 
    
 File size94765bytes 
 MD523d7d57fa37c5882cb9a4fcf0652615d 
    
    
 ThreatExpertOther source 
 ThreatExpert:Report 
 Anubis:Report 
 VirusTotal:Report 
    
 First received03.22.2009 10:25:32 (CET) 
 Results9/39 (23.08%) 
    
 Alias:SHeur2.WXJ 
  Trojan-Downloader.Win32.FraudLoad.dxh 
  Sus/FakeAV-A 
  Trojan-Dropper.Agent (Sig-Id:315644) [Ikarus Virus Scanner] 

Result when running:
 SystemSecurity WinWebSecurity
SystemSecurity WinWebSecurity

HTTP Request: 94.247.3.74:80 - [webnetsafety.com]
Request: GET /install/ws.zip


 File info:av.exe  
  av.glu (config file) 
    
 File size 315392 bytes 
 MD5f54d79a2fb5e0b21a4caf6cbe165b839 
    
    
 VirusTotal:Report 
    
 First received03.22.2009 00:02:45 (CET) 
 ResultsResult: 3/39 (41.03%) 
    
 Alias:(Suspicious) - DNAScan [CAT-QuickHeal] 
  Suspicious File [eSafe] 
  Win32.FraudLoad.vmsd [Kaspersky] 


Application screenshot:
 SystemSecurity - WinWebSecurity: Application Screenshot