<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1670645896303580754</id><updated>2012-02-10T08:42:57.244-08:00</updated><category term='spyware'/><category term='worm'/><category term='rogue'/><category term='phishing research'/><category term='trojan'/><category term='adware'/><category term='ransomware'/><category term='papers'/><title type='text'>Malware Disasters Team</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5674901304121665304</id><published>2011-04-11T18:44:00.000-07:00</published><updated>2011-04-11T18:44:14.640-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing research'/><title type='text'>Increase in Dutch banking phishing</title><content type='html'>&lt;div style="text-align: justify;"&gt;The last few months there was an increase in a phishing campaign targeted on customers from Rabobank and ING, two major banks in The Netherlands and Belgium. Some examples of a phishing mail:&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-i-DM77ulMIw/TaOsYMNJvZI/AAAAAAAAAcQ/FThX3p6hn3I/s1600/p1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="315" src="http://1.bp.blogspot.com/-i-DM77ulMIw/TaOsYMNJvZI/AAAAAAAAAcQ/FThX3p6hn3I/s400/p1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Phishing email for ING with the subject “Account Verificatie” (or in English: “Account Verification”) &lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-doKHmpomUpk/TaOsiVkm37I/AAAAAAAAAcU/4eBNn8hOk54/s1600/p2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-doKHmpomUpk/TaOsiVkm37I/AAAAAAAAAcU/4eBNn8hOk54/s400/p2.jpg" width="372" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Phishing email for Rabobank with the subject “Customer Services Update”.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;If you speak the Dutch language, you notice the content of the emails are actually more different than most phishing mails. In fact there’s a bigger variety, and in the first version there is almost no grammatical or spelling error. The second email - for Rabobank- however, is clearly a Google Translate copy/paste job.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;All emails seem to be originating from valid email addresses, domains are pointing to @rabobank.nl and @ing.nl , which are in fact legitimate addresses from the two banks.&lt;br /&gt;However, if we check the message headers we can see IP’s originating from Nigeria:&lt;/div&gt;&lt;br /&gt;&lt;a href="http://whois.domaintools.com/41.155.32.70" style="color: orange;"&gt;41.155.32.70&lt;/a&gt; – &lt;a href="http://ipvoid.com/scan/41.155.32.70" style="color: orange;"&gt;IPVoid results&lt;/a&gt;&lt;br /&gt;&lt;a href="http://whois.domaintools.com/82.128.38.67" style="color: orange;"&gt;82.128.38.67&lt;/a&gt; – &lt;a href="http://ipvoid.com/scan/82.128.38.67" style="color: orange;"&gt;IPVoid results&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Another IP address is originating from New Zealand and is actually blacklisted on several blacklists, as can be confirmed when checking with IPVoid:&lt;/div&gt;&lt;br /&gt;&lt;a href="http://whois.domaintools.com/203.97.33.68" style="color: orange;"&gt;203.97.33.68&lt;/a&gt; – &lt;a href="http://ipvoid.com/scan/203.97.33.68" style="color: orange;"&gt;IPVoid results&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;This means the email-addresses are spoofed to trick users into believing the email is valid.&lt;br /&gt;Now, what happens if you click on the link included in the message?&amp;nbsp; You will be redirected to any of these pages: &lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-qpDcW43u_hg/TaOstD0-c8I/AAAAAAAAAcY/HiyDUKBT_TY/s1600/p3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="303" src="http://3.bp.blogspot.com/-qpDcW43u_hg/TaOstD0-c8I/AAAAAAAAAcY/HiyDUKBT_TY/s400/p3.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Phishing website for ING. The user needs to login with his/her username and password. You can also opt to login with the ‘calculator’. The calculator is in fact a card reader which you can use to login.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-M2ajwiuHOVo/TaOs3ATjGYI/AAAAAAAAAcc/ydE9F89XE58/s1600/p4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://3.bp.blogspot.com/-M2ajwiuHOVo/TaOs3ATjGYI/AAAAAAAAAcc/ydE9F89XE58/s400/p4.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Phishing website for Rabobank.&amp;nbsp; You can login using your account number, access code, and PIN code. You can also use your card reader.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The intention of these emails is of course to steal user credentials and empty the account of the duped user. These attacks are pretty well orchestrated. If you click on any of the links on the phishing page, it will redirect you to the real ING website which provides extra information on the topic you clicked on.&lt;/div&gt;&lt;br /&gt;The following tips do not only apply to the above story, but apply to any other (suspicious) email you receive:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Do not click on any of the links (or anything for that matter) in the email you have received.&lt;/li&gt;&lt;li&gt;Do not reply to the email.&lt;/li&gt;&lt;li&gt;Delete the email immediately, certainly if you are not a customer of the aforementioned bank or did not order anything, changed your password, and so on.&lt;/li&gt;&lt;li&gt;If you really need to access or check your bank account, visit the website directly by typing the address in your browser’s address bar. Also verify the URL starts with https instead of http.&lt;/li&gt;&lt;li&gt;Another useful trick is to hover over the link in the email. In the bottom left corner you should be able to see the real address behind the URL displayed.&lt;/li&gt;&lt;li&gt;When in doubt, you can double-check using URL scanning services such as&lt;a href="http://www.virustotal.com/"&gt; &lt;span style="color: orange;"&gt;VirusTotal&lt;/span&gt;&lt;/a&gt; or &lt;a href="http://www.urlvoid.com/" style="color: orange;"&gt;URLVoid&lt;/a&gt; by &lt;a href="http://www.malwareint.com/part.html" style="color: orange;"&gt;our partner&lt;/a&gt; &lt;a href="http://www.novirusthanks.org/" style="color: orange;"&gt;NoVirusThanks&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Bart Parys&lt;br /&gt;Malware Research&lt;br /&gt;Twitter: @bartblaze&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5674901304121665304?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5674901304121665304/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2011/04/increase-in-dutch-banking-phishing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5674901304121665304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5674901304121665304'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2011/04/increase-in-dutch-banking-phishing.html' title='Increase in Dutch banking phishing'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-i-DM77ulMIw/TaOsYMNJvZI/AAAAAAAAAcQ/FThX3p6hn3I/s72-c/p1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2403227417412601442</id><published>2011-02-21T02:06:00.000-08:00</published><updated>2011-02-21T05:53:01.196-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='papers'/><title type='text'>New whitepaper about Carberp Botnet</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s1600/inside-carberp-botnet-en.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s200/inside-carberp-botnet-en.png" width="141" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Is available a &lt;a href="http://www.malwareint.com/docs.html" style="color: orange;"&gt;new whitepaper&lt;/a&gt; that describes the operation of one of the botnets "wanted" by the security community:&lt;b&gt; Carberp&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;The article, called &lt;b&gt;Inside Carberp Botnet&lt;/b&gt; and written by Francisco Ruiz, Crimeware Research of &lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt;, details the different parts of this crimeware, leaving evidence of its full operating mode.&lt;br /&gt;&lt;br /&gt;In recent weeks, has returned to Carberp impact due to the revival of several of his former C&amp;amp;C. However, experts believe &lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; have concrete evidence that would demonstrate that in fact the original group that was behind the first generation of Carberp is broken, and that some of the new botnets that spread banking trojan Carberp are managed through a modified version of the original.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; have a &lt;b&gt;Carberp Working Group&lt;/b&gt;, responsible for private research and demand of this particular threat. &lt;a href="http://malwareint.blogspot.com/2011/02/inside-carberp-botnet.html" style="color: orange;"&gt;In the main blog&lt;/a&gt;, Ruiz also said that a botnet Carberp private market in a very closed environment, but since a few days ago, the marketing model has been released, giving some details of its current features and costs.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2403227417412601442?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2403227417412601442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2011/02/new-whitepaper-about-carberp-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2403227417412601442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2403227417412601442'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2011/02/new-whitepaper-about-carberp-botnet.html' title='New whitepaper about Carberp Botnet'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s72-c/inside-carberp-botnet-en.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-225483414632936282</id><published>2011-02-14T12:10:00.000-08:00</published><updated>2011-02-15T04:35:50.364-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Facebook rogue applications still lurking around</title><content type='html'>For quite some time now there are rogue applications&amp;nbsp; trying to convince you that you are able to check whoever viewed your profile. There are a lot of different names for this rogue application, some but not all include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;creep exterminators&lt;/li&gt;&lt;li&gt;catch them being creepy&lt;/li&gt;&lt;li&gt;creepy profile peekers&lt;/li&gt;&lt;li&gt;privacy bros &lt;/li&gt;&lt;li&gt;we catch stalkers &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;So what will this fake application do? For starters, it will surely NOT show you who's been viewing your profile.&amp;nbsp; If you land on this application, you will be presented with the following screen:&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-OKjJhNlwTEw/TVmJP3wj1NI/AAAAAAAAAbU/YW48C6idk_8/s1600/MI-MD_prof.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="246" src="http://4.bp.blogspot.com/-OKjJhNlwTEw/TVmJP3wj1NI/AAAAAAAAAbU/YW48C6idk_8/s400/MI-MD_prof.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;b&gt;Profile Creeps application&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-pQjYVyGADSQ/TVmQaJ2U03I/AAAAAAAAAbk/QNyHDyXs7A0/s1600/MI-MD-face.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="221" src="http://3.bp.blogspot.com/-pQjYVyGADSQ/TVmQaJ2U03I/AAAAAAAAAbk/QNyHDyXs7A0/s400/MI-MD-face.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;b&gt;Request for permission&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;You then have to allow access from the application so they can show you who's been lurking around your profile. But wait ! You first have to complete a survey and then you are able to check it out. Simple, right?&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-MRI6PsEgGvk/TVmJ6GQot1I/AAAAAAAAAbc/PS2-GLV-EEk/s1600/MI-MD_fee.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="299" src="http://3.bp.blogspot.com/-MRI6PsEgGvk/TVmJ6GQot1I/AAAAAAAAAbc/PS2-GLV-EEk/s400/MI-MD_fee.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;b&gt;Facebook verification&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Not exactly. These fake surveys are pretty common on the internet. It is a typical scam. For example, I had one particular survey that urged me to download SmileyCentral, the other tried to deliver me Webfetti.&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=3aea99720c89ca1b6552e0b10624cf6ad86d65bad6e659599019c9029bdcec8b-1297697679" style="color: orange;"&gt;9ed197b533fdf53ab8cf9e83a1b5951d&lt;/a&gt; (&lt;b&gt;Webfetti.exe&lt;/b&gt;)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=ef70b622c8b53c4f286127151ff41be799896de49d0d10e75a673bffcea7ee30-1297688529" style="color: orange;"&gt;ff8d221113615909b07b1ba9ceb8466a&lt;/a&gt; (&lt;b&gt;SmileyCentralPFSetup2.3.78.2.NoSA.NoHP.ZNfox000.exe&lt;/b&gt;)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Another fake survey wanted me to fill in my phone number, and afterwards send an (expensive) text message to 'unlock' the application. In addition to letting you fall into one of these scams, the rogue application also promotes itself on all of your friends’ walls:&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--A7VvN-kr18/TVmKNJ5kAjI/AAAAAAAAAbg/Bb9LMs4E5G4/s1600/MI-MD_rogue.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="66" src="http://1.bp.blogspot.com/--A7VvN-kr18/TVmKNJ5kAjI/AAAAAAAAAbg/Bb9LMs4E5G4/s400/MI-MD_rogue.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;b&gt;Rogue application spreading itself on other people’s wall&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/center&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;If you would like to remove it, follow the steps below:&lt;br /&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;Go to your Facebook profile. Find the post that mentions the "stalker" application&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Skim over it and you will see an X appear. Click on it and choose  "Remove (name of the fake application here)". &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Additionally, you can also report it as abusive to help in stopping these type of applications.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Next step is to click on My Account and choose Privacy Settings. Down below you can see "Apps and websites". Click on Edit your settings. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Select Remove unwanted or spammy apps. You can now Edit the application and remove it.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Bart Parys &lt;br /&gt;Malware Research&lt;br /&gt;twitter: &lt;a href="https://twitter.com/bartblaze" style="color: orange;"&gt;@bartblaze&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-225483414632936282?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/225483414632936282/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2011/02/facebook-rogue-applications-still.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/225483414632936282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/225483414632936282'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2011/02/facebook-rogue-applications-still.html' title='Facebook rogue applications still lurking around'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-OKjJhNlwTEw/TVmJP3wj1NI/AAAAAAAAAbU/YW48C6idk_8/s72-c/MI-MD_prof.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-8435682174595767666</id><published>2011-01-30T07:47:00.000-08:00</published><updated>2011-01-30T07:48:42.881-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><title type='text'>Big Brother Brazil 2011 (AKA BBB 2011) malware attack</title><content type='html'>&lt;div style="text-align: justify;"&gt;Big Brother 2011 (AKA BBB 2011) begins in Brazil and it's a motivation for social engineering attacks.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Big Brother Brasil 2011 began on January 11th in Brazil and malware authors should be celebrating, thus, because this is something very popular so it's easy to attract victims (via social engineering) to 'see' videos or pictures of the BBB 2011 participants.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We will show you a threat which came in form of a phishing and using social engineering ask recipients to click in a link in order to watch a video of a transsexual which is making the man's participants of the BBB 2011 confused.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As you can see on the original e-mail below, the attacker uses a technique known as DHA (&lt;a href="http://en.wikipedia.org/wiki/Directory_Harvest_Attack" style="color: orange;"&gt;Directory Harvest Attack&lt;/a&gt;) against the @hotmail.com domain in order to send the phishing message to valid e-mail addresses.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TUV6w2H7yzI/AAAAAAAAAaw/1zfX6MLXWXU/s1600/1-MI_First-Phishing+Message+received.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="263" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TUV6w2H7yzI/AAAAAAAAAaw/1zfX6MLXWXU/s400/1-MI_First-Phishing+Message+received.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Note that when you move the mouse to the link which appears that will get you to the youtube.com, on the status bar you can see that it will not get you to the youtube.com website. It will get you to the website hxxp://twurl.nl/rbpm6s.&lt;/div&gt;&lt;br /&gt;Below you have the source code of the phishing message:&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtTQ0w9Ng==&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;X-Message-Status: n&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;X-SID-PRA: globo.com (BBB 2011) &lt;/span&gt;&lt;/i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;X-SID-Result: Fail&lt;br /&gt;X-DKIM-Result: None&lt;br /&gt;X-AUTH-Result: FAIL&lt;br /&gt;X-Message-Info: DkpufaDli9Iih8M1I3rOCBHB3/E1htFb2qXrXVLfpfjlNFuHVG90WYrx2zq5Mw1fmsHKOjL4weQGCOatyx0Pn7FYN0czafnY9kSTqtv24cY=&lt;br /&gt;Received: from wl01.ws.poa.ige ([201.94.125.1]) by col0-mc3-f16.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Tue, 18 Jan 2011 10:21:08 -0800&lt;br /&gt;Received: from wl01.ws.poa.ige (dcrs8211 [127.0.0.1])&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; by wl01.ws.poa.ige (8.13.8/8.13.8) with ESMTP id p0IH1auJ030937;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tue, 18 Jan 2011 15:01:36 -0200&lt;br /&gt;Received: (from httpd@localhost)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; by wl01.ws.poa.ige (8.13.8/8.13.8/Submit) id p0IH1ZXl030933;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tue, 18 Jan 2011 15:01:35 -0200&lt;br /&gt;To: baa@hotmail.com, bbb@hotmail.com, bcc@hotmail.com,&lt;br /&gt;bdd@hotmail.com, bee@hotmail.com&lt;br /&gt;Subject: ariadna (transesual) no bbb 2011 deixa homens confuso....&lt;br /&gt;X-PHP-Script: mylove2010.info/catastrofe/feed10.php for 187.57.247.86&lt;br /&gt;Date: Tue, 18 Jan 2011 15:01:34 -0200&lt;br /&gt;From: "globo.com (BBB 2011)" &lt;/span&gt;&lt;/i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;Reply-to: "globo.com (BBB 2011)" &lt;/span&gt;&lt;/i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;Message-ID: &amp;lt;63a5faa6442cd3b2f870f2ac7a99bde7@mylove2010.info&amp;gt;&lt;br /&gt;X-Priority: 3&lt;br /&gt;X-Mailer: Microsoft Outlook Express 6.00.2800.1409&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.10.2800.1409.1718742875.rg.sm31&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Transfer-Encoding: 8bit&lt;br /&gt;Content-Type: text/html; charset="iso-8859-1"&lt;br /&gt;Return-Path: httpd@wl01.ws.poa.ige&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;----------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;As you can see on the source code, this phishing message involves three main characteristics:&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;i&gt;A file named feed10.php&lt;/i&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; A file named ariedina.jpg3&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; A link pointing to the website hxxp://twurl.nl/rbpm6s.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TUV8pbvI-ZI/AAAAAAAAAa4/qGykMcNWTew/s1600/2-MI_second-feed10-php.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="294" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TUV8pbvI-ZI/AAAAAAAAAa4/qGykMcNWTew/s400/2-MI_second-feed10-php.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;b&gt;Analyzing the file feed10.php&lt;/b&gt;&lt;br /&gt;I have downloaded this script page by using the webget utility. See the screenshot below:&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: center;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;wget -v mylove2010.info/catastrofe/feed10.php&lt;/span&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; As you can see above, this is a smtp engine used by this threat. Just in case I have submitted this PHP script to virustotal and &lt;a href="http://www.virustotal.com/file-scan/report.html?id=45c74823c2888277c1feaf706cc08a032da3557d56e2d7053d88069306b25c96-1295920917" style="color: orange;"&gt;you can see the results&lt;/a&gt;. This sounds a true smtp engine script, so there is no malware associated to this program, while it might be used by malwares.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;&lt;b&gt; Analyzing the file ariedina.jpg3&lt;/b&gt;&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; This is just a picture which is used to attract people to click and see a 'video' at youtube.com, however, as you can see on the source code there is a HREF instruction so when the user clicks on this picture (anywhere) it will get the user to the malicious website: hxxp://twurl.nl/rbpm6s&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;I have downloaded this picture so I could analyze it and saw that it's really just a picture:&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: center;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;wget -v http://lh4.ggpht.com/_FJQwbg0nrOk/TTGRJVC1KtI/AAAAAAAAAMs/CUvYCECUkhM/ariedina.jpg3&lt;/span&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TUV-QnoFyJI/AAAAAAAAAa8/N3j1bO7DrgE/s1600/3-MI_third-wget+on+the+ariedinaJPG3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="183" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TUV-QnoFyJI/AAAAAAAAAa8/N3j1bO7DrgE/s400/3-MI_third-wget+on+the+ariedinaJPG3.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; I have submitted this file to the virustotal website so you can get the report using the link below. There are &lt;a href="http://www.virustotal.com/file-scan/report.html?id=67d170fce9a3b21411cb07a9a1e3ca6de78fff95f997a747fd3bba5400f353c3-1295920946" style="color: orange;"&gt;no detection&lt;/a&gt; since this is just a picture.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;&lt;b&gt;Analyzing the link hxxp://twurl.nl/rbpm6s&lt;/b&gt;&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; Using wget pointing to the URL hxxtp://twurl.nl/rbpm6s resulted in downloading a file named youtube_video756.exe.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: center;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; wget -v http://twurl.nl/rbpm6s&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;br /&gt;&lt;b&gt;Analyzing youtube_video756.exe&lt;/b&gt;&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; After submitting this sample to &lt;a href="http://www.virustotal.com/file-scan/report.html?id=522ef5780f2973f5e01853287619df0ddf1c4447ba6c0dcd3d6591b4778423d5-1295921002" style="color: orange;"&gt;virustotal&lt;/a&gt; you can see that some AV vendors detects this threat. Some of them using signatures and a couple of them using a in-cloud technology.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;If you run youtube_video756.exe, it will basically perform the following activities:&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; Create a copy of itself using a file named Recorte de tela e Iniciador do OneNote 2007.exe on the folder "C:\Documents and Settings\%user%\Start Menu\Programs\Startup\". This process is then launched.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;It connects to the ftp site ftp.biancarox.net using the username cohabrox and a password which will not be reported here just in case. It downloads 10 files (listed below) to the folder C:\documents and setings\%user%\. While all of these files have a .txt extension, they are not a true .txt file. Looking at its strings you can see that they are really executables.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TUWDgsLT-gI/AAAAAAAAAbA/IwkwiYHhSqI/s1600/4-MI_trojan+has+downloaded+10+files.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="181" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TUWDgsLT-gI/AAAAAAAAAbA/IwkwiYHhSqI/s400/4-MI_trojan+has+downloaded+10+files.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;Taking a look at the process strings (below), we can see several internet bank sites of Brazil and two webmail websites.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TUWEUFT64SI/AAAAAAAAAbE/9aFPewNpOOE/s1600/5-MI_strings+on+memory-target+banks+websites.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TUWEUFT64SI/AAAAAAAAAbE/9aFPewNpOOE/s400/5-MI_strings+on+memory-target+banks+websites.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;When you open Internet Explorer and type one of the target URLs, like www.bradesco.com.br (which is a true bank of Brazil), it will kill iexplorer.exe and will load a new process C:\Document and Settings\%user%\®¢Ÿª¤ª¥ž¥.txt. If you type anoher URL on the IE address bar like www.bradescoprime.com.br, another process will be launched on this case it would be the ®ž“§«š§«š.txt.&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; This process is a fake application which emulates the requested website and it will capture your bank agency, account, token, passwords, etc. See screenshots below:&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TUWFYX0ULmI/AAAAAAAAAbI/5Dg8SLYBHHE/s1600/6-MI_one+of+the+fake+websites-typing+bank+agency+and+account.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TUWFYX0ULmI/AAAAAAAAAbI/5Dg8SLYBHHE/s400/6-MI_one+of+the+fake+websites-typing+bank+agency+and+account.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; While you are typing your bank agency, account, password, token, etc, the trojan is capturing everything and is written it to a *.bsp file on the C:\Documents and settings\%user%\. Below you have an example:&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TUWFxPEbkwI/AAAAAAAAAbM/RiqJNBjgchY/s1600/10-MI_TXT+file+generated+by+the+trojan+with+all+of+my+passwords-data.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="136" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TUWFxPEbkwI/AAAAAAAAAbM/RiqJNBjgchY/s400/10-MI_TXT+file+generated+by+the+trojan+with+all+of+my+passwords-data.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;&lt;b&gt;Indicators of compromise&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Check for the existence of the following MD5 on the C:\Documents and Settings\%user%\. &lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;i&gt;edaa81ad2165c65bb340e636bf642291&lt;/i&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; b82c51f94b0e516f461b6f84a668dfde&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; 76184bebea96f59086368b64a896d224&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; f590d18d7b50109c03c6237d86e8415d&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; 52ea037028eb2274147aef1edfb64865&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; daa21069ae179cc0f195cd42795b592b&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; 86802efad8fb5b8153d7c7de67cb66bb&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; fc7592c9f2e2264c687a806459387d30&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; 9547ff6be241b5bb8a87f0dabe3b3218&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; 5cd6a3ac2b2d97e36091a1ecd2fd0aec&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  Check if the process Recorte de tela e Iniciador do OneNote 2007.exe is running or present on the folder C:\Documents and Settings\*\Start Menu\Programs\Startup\ (it's MD5 is d34c8d3ad55f65d701264a5e8e278915)&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/div&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;br /&gt;Network connections to:&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;i&gt;hxxp://mylove2010.info/catastrofe/feed10.php&lt;/i&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; hxxp://twurl.nl/rbpm6s&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; hxxp://livinianot.com.br/&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; ftp.biancarox.net&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  Below you have a report from VirusTotal regarding the samples that we have analyzed here:&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=968db70645fceeb734ba941ee78d51848057762b0559709238c59d4391d1c25e-1295986300" style="color: orange;"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;id=968db70645fceeb734ba941ee78d51848057762b0559709238c59d4391d1c25e-1295986300&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;i style="color: orange;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;a href="http://www.virustotal.com/file-scan/report.html?id=961a9c536b98d02172eb48bd2e0e4881591ac1eb607bf1ea7f267f4994c6b6f6-1295986210"&gt;id=961a9c536b98d02172eb48bd2e0e4881591ac1eb607bf1ea7f267f4994c6b6f6-1295986210&lt;/a&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;br /&gt;&lt;i style="color: orange;"&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;  &lt;a href="http://www.virustotal.com/file-scan/report.html?id=e6a33cbba7e6348c41cb7e10acac4efaf47286603d54d1c7088f8772bb0f23e8-1295986257"&gt;id=e6a33cbba7e6348c41cb7e10acac4efaf47286603d54d1c7088f8772bb0f23e8-1295986257&lt;/a&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=4e908de9a38bb3b90435b0d8b733ad11836a8f65bff2cd6cd247fd47a332af16-1295996254" style="color: orange;"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; id=4e908de9a38bb3b90435b0d8b733ad11836a8f65bff2cd6cd247fd47a332af16-1295996254&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=d12ef9562f2deae6ef8e7d5842bf1f1425fc23ce7b6c2265a62189eac14e966f-1295985855"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; &lt;span style="color: orange;"&gt;id=d12ef9562f2deae6ef8e7d5842bf1f1425fc23ce7b6c2265a62189eac14e966f-1295985855&lt;/span&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=8d1a2ece03010fe9610c852a70d13c22f9e91d93e39abc939a742d84b279ea64-1295996475"&gt;  &lt;span style="color: orange;"&gt;id=8d1a2ece03010fe9610c852a70d13c22f9e91d93e39abc939a742d84b279ea64-1295996475&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=457278ad3bc382dd5159c0be8e9f2f2e3e1cf9191861b56497c81f21f423808d-1295996615" style="color: orange;"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;id=457278ad3bc382dd5159c0be8e9f2f2e3e1cf9191861b56497c81f21f423808d-1295996615&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=55d9afec1ad24fcfec03f03cbc7be9b6c21a614db87432e925cdc8112c551c5e-1295996949"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=1670645896303580754&amp;amp;postID=8435682174595767666"&gt;  &lt;span style="color: orange;"&gt;id=55d9afec1ad24fcfec03f03cbc7be9b6c21a614db87432e925cdc8112c551c5e-1295996949&lt;/span&gt;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=73cc47196be7bd8c0f7764a46cb4488266bef2ea1ffccbdbd91cd0b62c79919d-1295997136"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=1670645896303580754&amp;amp;postID=8435682174595767666"&gt;  &lt;span style="color: orange;"&gt;id=73cc47196be7bd8c0f7764a46cb4488266bef2ea1ffccbdbd91cd0b62c79919d-1295997136&lt;/span&gt;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=26f542326786e4facd624fcb170a71c6a2e709e23c8f4cffa4715e133869316b-1295980568"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=1670645896303580754&amp;amp;postID=8435682174595767666"&gt; &lt;span style="color: orange;"&gt;id=26f542326786e4facd624fcb170a71c6a2e709e23c8f4cffa4715e133869316b-1295980568&lt;/span&gt;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=8f5c8ad99ded74d3cc233b691a803fc6f00ac3113ad67c6f6802ac3ea0f727fc-1295389644"&gt;&lt;i&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=1670645896303580754&amp;amp;postID=8435682174595767666"&gt; &lt;span style="color: orange;"&gt;id=8f5c8ad99ded74d3cc233b691a803fc6f00ac3113ad67c6f6802ac3ea0f727fc-1295389644&lt;/span&gt;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;communications_msn_cs_ptbr@microsoft.windowslive.com&gt; Bruno Caseiro&lt;br /&gt;Malware Researcher&lt;br /&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;/communications_msn_cs_ptbr@microsoft.windowslive.com&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-8435682174595767666?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/8435682174595767666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2011/01/big-brother-brazil-2011-aka-bbb-2011.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8435682174595767666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8435682174595767666'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2011/01/big-brother-brazil-2011-aka-bbb-2011.html' title='Big Brother Brazil 2011 (AKA BBB 2011) malware attack'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TUV6w2H7yzI/AAAAAAAAAaw/1zfX6MLXWXU/s72-c/1-MI_First-Phishing+Message+received.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6682517488033209934</id><published>2010-10-27T09:07:00.000-07:00</published><updated>2010-10-27T09:07:57.530-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>SMS Ransomware. From Russia to the world</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TMhNJMqDItI/AAAAAAAAAag/_RG_7j1iNJ8/s1600/MI-ransom_23102010.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The new generation of malicious code designed to increase the economic life of criminal groups through exercises that involve sending a text SMS message rate, is now a pattern that has already spread worldwide.&lt;br /&gt;&lt;br /&gt;While this type of ransomware is developed for the Russian-speaking public, being a very common malware in Russia, any user anywhere in the world is a potential victim.&lt;br /&gt;&lt;br /&gt;Daily offenders change the graphic design of what is shown on screen, although minimalist very aggressive, and always providing the necessary information so that, in theory, the victim can get the key to unlock access to the operating system, clear that exchange for a sum of money in this case, amounts to 360 rubles (just over $ 10).&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TMhNJMqDItI/AAAAAAAAAag/_RG_7j1iNJ8/s1600/MI-ransom_23102010.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TMhNJMqDItI/AAAAAAAAAag/_RG_7j1iNJ8/s400/MI-ransom_23102010.png" width="400" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;b&gt;SMS Ransomware template&lt;/b&gt;&lt;br /&gt;&lt;i&gt;The latest campaign to spread and infection of this family of ransomware, occurs with this design.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The truth is that despite not having a complex structure around its development; represent one of the malicious codes more aggressive and invasive. Not only because by blocking the system also blocks the ability to access any functionality and operating system software, but also while the user looks ransomware design, it’s reported against an affiliate business (usually the type Pay-per-Install), and in some cases, trying to steal information related to authentication credentials.&lt;/div&gt;&lt;b&gt;&lt;br /&gt;Related Information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/10/new-variante-of-sms-ransomware-itw.html"&gt;New variant of SMS Ransomware ItW&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/microsoft-security-antivirus-ransomware.html" style="color: orange;"&gt;Microsoft Security Antivirus ransomware&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/new-sms-ransomware-template-with-slight.html" style="color: orange;"&gt;New SMS ransomware template with slight change&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html"&gt;&lt;span style="color: orange;"&gt;Campaign to disseminate russian ransomware&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;New Russian SMS ransomware In-the-Wild&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html" style="color: orange;"&gt;SMS Ransomware porn template update&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6682517488033209934?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6682517488033209934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/10/sms-ransomware-from-russia-to-world.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6682517488033209934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6682517488033209934'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/10/sms-ransomware-from-russia-to-world.html' title='SMS Ransomware. From Russia to the world'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TMhNJMqDItI/AAAAAAAAAag/_RG_7j1iNJ8/s72-c/MI-ransom_23102010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5214501182695016322</id><published>2010-10-20T20:07:00.000-07:00</published><updated>2010-10-21T21:00:08.848-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New variant of SMS Ransomware ItW</title><content type='html'>&lt;div style="text-align: justify;"&gt;Malicious code types Ransomware have become more emphatically positioned on the stage of the business malicious round about malware.&lt;br /&gt;&lt;br /&gt;In this respect, far left the programs in this style using complex encryption algorithms exploiting conventional&amp;nbsp; aspects of cryptovirologhy, to meet at the present with a sort of ransomware seeking to block access to the victim operating system, calling for minimum sums but daily feed back the economy by criminal groups.&lt;/div&gt;&lt;br /&gt;This time, the template used is referred to in the following screenshot:&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TL-tdvpmjpI/AAAAAAAAAac/2OYrncoppA0/s1600/MIransom201002010.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TL-tdvpmjpI/AAAAAAAAAac/2OYrncoppA0/s400/MIransom201002010.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;SMS Ransomware&lt;/b&gt;&lt;br /&gt;&lt;i&gt;New variant of SMS Ransomware requesting the sum of 400 rublos (Russian money)&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;This new variant is another example similar to the family those previously propagated, with the particularity of incorporating number keys&amp;nbsp; on-screen, needed to "write" the number that will unlock the system.&lt;br /&gt;&lt;br /&gt;This maneuver isn't capricious and responds to the strategic defensive and evasive to block the use of the keyboard, precluding any attempt to access internal programs of the affected system.&lt;br /&gt;&lt;br /&gt;Although this new generation of ransomware aggressive approach does not address the abduction expressed by old programs in this category as GPCode malware, but is an extremely invasive and difficult to eradicate if it does not provide preventive tools available to protect infections of this caliber.&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Related Information &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/jorgemieres" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/microsoft-security-antivirus-ransomware.html" style="color: orange;"&gt;Microsoft Security Antivirus ransomware&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/new-sms-ransomware-template-with-slight.html" style="color: orange;"&gt;New SMS ransomware template with slight change&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html"&gt;&lt;span style="color: orange;"&gt;Campaign to disseminate russian ransomware&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;New Russian SMS ransomware In-the-Wild&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html" style="color: orange;"&gt;SMS Ransomware porn template update&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5214501182695016322?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5214501182695016322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/10/new-variante-of-sms-ransomware-itw.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5214501182695016322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5214501182695016322'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/10/new-variante-of-sms-ransomware-itw.html' title='New variant of SMS Ransomware ItW'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TL-tdvpmjpI/AAAAAAAAAac/2OYrncoppA0/s72-c/MIransom201002010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-1806289926568240252</id><published>2010-09-13T16:59:00.000-07:00</published><updated>2010-09-14T07:36:05.618-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>Microsoft Security Antivirus ransomware</title><content type='html'>&lt;div style="text-align: justify;"&gt;Criminal groups from Russia are trying constantly to raise money fraudulently, maliciously re-launched a proposal through a ransomware. In this case, the strategy is to display a window that is positioned in the center of the desktop, displaying a message in Russian under the title "&lt;b&gt;Microsoft Security Antivirus&lt;/b&gt;".&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TI64Ud80dcI/AAAAAAAAAZU/H66fw-Y_kgE/s1600/MI_MSA-Ransom.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TI64Ud80dcI/AAAAAAAAAZU/H66fw-Y_kgE/s320/MI_MSA-Ransom.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Ransomware opening message&lt;/b&gt;&lt;br /&gt;&lt;i&gt;The window displayed by the ransomware is located in the center of the screen and block any possibility to access Windows programs&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TI65PV_LzxI/AAAAAAAAAZc/wF7w7WL0ACk/s1600/MI_ransom-400.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;This malware is part of the same family that has plagued Internet ransom and are expressed through different designs, some more aggressive than others but ultimately with the same magnitude of risk and same objectives.&lt;br /&gt;&lt;br /&gt;Although this variant does not endorse any websites with pornographic content, claims his reward through a text message SMS rate in this case, the number &lt;b&gt;89030064850&lt;/b&gt;. The reward consists of being the payment of &lt;b&gt;400 rubles&lt;/b&gt; (Russian currency).&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TI65PV_LzxI/AAAAAAAAAZc/wF7w7WL0ACk/s1600/MI_ransom-400.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TI65PV_LzxI/AAAAAAAAAZc/wF7w7WL0ACk/s320/MI_ransom-400.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Reward Request&lt;/b&gt;&lt;br /&gt;&lt;i&gt;In this way the offender makes an economic profit at the expense of a mechanism fraudulent and illegal, in many cases, requires users to pay the amount of money without a guarantee that you will receive the unlock key&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The ransomware have become commonplace, providing a highly resource exploited by computer criminals who through affiliate systems collect the profits and manage the spread of the threat using specific crimeware.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://siri-urz.blogspot.com/" style="color: orange;"&gt;S!Ri&lt;/a&gt; has published some unlock codes can be used to regain control of the system. Thanks S!Ri&lt;br /&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030139823&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030065742&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b&gt;77294738T&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030064258&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030064960&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030065384&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89030139997&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b&gt;720194320Q&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Related Information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/jorgemieres" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/new-sms-ransomware-template-with-slight.html" style="color: orange;"&gt;New SMS ransomware template with slight change&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html"&gt;&lt;span style="color: orange;"&gt;Campaign to disseminate russian ransomware&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;New Russian SMS ransomware In-the-Wild&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html" style="color: orange;"&gt;SMS Ransomware porn template update&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-1806289926568240252?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/1806289926568240252/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/microsoft-security-antivirus-ransomware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1806289926568240252'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1806289926568240252'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/microsoft-security-antivirus-ransomware.html' title='Microsoft Security Antivirus ransomware'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TI64Ud80dcI/AAAAAAAAAZU/H66fw-Y_kgE/s72-c/MI_MSA-Ransom.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-8983672555630827107</id><published>2010-09-08T19:15:00.000-07:00</published><updated>2010-09-08T19:15:15.230-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New SMS ransomware template with slight change</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBdiVMsWI/AAAAAAAAAYs/gKIL4ymHy-w/s1600/MI_ransom-350.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Recently a new variant of SMS ransomaware family that spread and promote pornographic sites, is In-the-Wild presenting a superficial makeover.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Several weeks ago a campaign is active through which spreads a variant of this type of ransomware, which displays a black window covering the entire desktop. This time, the window does not cover the entire desktop but is located in the center of it, but disables any possibility to access any of the applications of the system.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;As in previous campaigns for the release request to send an SMS message such as a certain number requesting the sum of, according to the variants detected so far, 350, 400 and 410 rubles (Russian money).&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBdiVMsWI/AAAAAAAAAYs/gKIL4ymHy-w/s1600/MI_ransom-350.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="221" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBdiVMsWI/AAAAAAAAAYs/gKIL4ymHy-w/s400/MI_ransom-350.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBroubxCI/AAAAAAAAAY0/_8UWsXIxqVg/s1600/MI_ransom-400.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;SMS &lt;/b&gt;&lt;b&gt;Ransomaware &lt;/b&gt;&lt;b&gt;asking for 350 rubles &lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBroubxCI/AAAAAAAAAY0/_8UWsXIxqVg/s1600/MI_ransom-400.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="221" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBroubxCI/AAAAAAAAAY0/_8UWsXIxqVg/s400/MI_ransom-400.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;SMS Ransomaware asking for 400 rubles &lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;For cases where the requested ransomware 410 rubles for a key to unlock the system can use any of the following keys to unlock provided &lt;a href="http://siri-urz.blogspot.com/" style="color: orange;"&gt;by SiR! from his blog&lt;/a&gt; (thanks SiR!):&lt;/div&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028516&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028759&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028794&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b&gt;403947563!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028519&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b&gt;$334327890$&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028477&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028491&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028518&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b&gt;$009264834$&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html"&gt;&lt;span style="color: orange;"&gt;Campaign to disseminate russian ransomware&lt;/span&gt; &lt;/a&gt;&lt;a href="http://twitter.com/jorgemieres" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;New Russian SMS ransomware In-the-Wild&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html" style="color: orange;"&gt;SMS Ransomware porn template update&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Jorge Mieres&lt;/b&gt;  &lt;br /&gt;Founder &amp;amp; Director of &lt;b&gt;Malware&lt;span class="blue"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;Crimeware &amp;amp; Intelligence Analyst Researcher&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-8983672555630827107?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/8983672555630827107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/new-sms-ransomware-template-with-slight.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8983672555630827107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8983672555630827107'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/new-sms-ransomware-template-with-slight.html' title='New SMS ransomware template with slight change'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIhBdiVMsWI/AAAAAAAAAYs/gKIL4ymHy-w/s72-c/MI_ransom-350.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-1774225821993849881</id><published>2010-09-02T19:18:00.000-07:00</published><updated>2010-09-03T08:34:25.120-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>Campaign to disseminate russian ransomware</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Updated 09/03/2010&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;S!Ri is doing a great job getting information needed to unlock this and other variants of ransomaware. Has kindly agreed to share with us their work by providing an update with new codes. Great job S!Ri and thank you very much for sharing data :)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028569&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028703&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b style="color: black;"&gt;!8912034'&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Number to Call: &lt;b&gt;89654028578&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028597&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028594&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028566&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028563&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028583&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028725&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028717&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028703&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b style="color: black;"&gt;(30958374)&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b style="color: red;"&gt;&amp;nbsp;&lt;/b&gt;&lt;b style="color: red;"&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Number to Call: &lt;b&gt;89654028562&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028563&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028590&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028595&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028598&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028578&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028614&lt;/b&gt;&lt;br /&gt;Number to Call: &lt;b&gt;89654028723&lt;/b&gt;&lt;br /&gt;Code to unlock Windows: &lt;b style="color: black;"&gt;~2058205~&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You can find more information about the type ransomware malware and rogue on his blog:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://siri-urz.blogspot.com/" style="color: orange;"&gt;http://siri-urz.blogspot.com&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;b&gt;Original 09/02/2010&lt;/b&gt; &lt;br /&gt;Every so often a new ransomware campaign designed to block access to the operating system by displaying a message which requests to send a text message SMS rate to a certain number, in theory, to receive a key to regain control access to the system.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIBYViizOsI/AAAAAAAAAW0/zjrSUKQeM0E/s1600/MI_ransom-russian.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="231" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIBYViizOsI/AAAAAAAAAW0/zjrSUKQeM0E/s400/MI_ransom-russian.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;SMS Ransomware&lt;/b&gt;&lt;br /&gt;&lt;i&gt;The window occupies the whole screen by closing access to any program. When you enter the correct password, the window disappears and the binary executable is self-eliminated.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The distribution of this ransomware is being carried out since late July and so far has more campaigns. All show the same message and design style, but change the phone number to be sent the text message. Some of the executables that are part of this campaign are:&lt;/div&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;vip_porno_12730.avi.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=153b5e59b4443b0832cab7456a88891c8fb1eb04c2f3e05a3a13084b5909dd62-1283384334" style="color: orange;"&gt;5b1d7ce7acf6de3e8b7d856bdc6127ba&lt;/a&gt;) - &lt;b&gt;PornoBlocker/LockScreen&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;vip_porno_49873.avi.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=13e9befa760ee385be462809f33f26488f24e7e17dec865362503b2dc3a7d59c-1283356844" style="color: orange;"&gt;20830c687b1535aefa1f281fb1c6a513&lt;/a&gt;) - &lt;b&gt;PornoBlocker/LockScreen&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;vip_porno_79341.avi.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=ab7500389535531b13b079004d983c563368e242586c6f0074af28bb809a5f7a-1283440320" style="color: orange;"&gt;6e4ecc96a88e36c9ec12d4b500aef331&lt;/a&gt;) - &lt;b&gt;PornoBlocker/LockScreen&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;vip_porno_81380.avi.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=e2b49e20de75631bdd79296ff05a0ea0eee4156b48cb8d5c90743849f8b81f54-1283261573" style="color: orange;"&gt;3c637427af826f877a50c5a8763fe4f0&lt;/a&gt;) - &lt;b&gt;PornoBlocker/LockScreen&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TIBZUSAzKdI/AAAAAAAAAW8/xXf3mAOrNqo/s1600/MI_100rubles.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The business of the offender is the percentage of money that is carried by each SMS that is recorded at these different numerical ranges, sent by the victims. The amount of money requested by the offender through the message to aspire to unlock access to the system is 400 rubles. That sum is expressed in Russian currency (рубль) and its equivalent in U.S. dollars is $ 13.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TIBZUSAzKdI/AAAAAAAAAW8/xXf3mAOrNqo/s1600/MI_100rubles.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TIBZUSAzKdI/AAAAAAAAAW8/xXf3mAOrNqo/s400/MI_100rubles.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;In all campaigns has appeared so far of this variant of ramsomware, provided the amount requested was 400 rubles.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Another peculiarity is that it belongs to the generation of ransom whose dissemination strategy is exploited using pornographic resources, either through websites or domains conditional content, using SEO strategies, are content with words that refer to the type of content referred to.&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Unlock the following codes:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89653625352&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;@34208923@&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89653686497&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;10779401&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89653276574&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;17661888&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89652404438&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;!48950345!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89646283842&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;10070000008000&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89636385700&lt;br /&gt;89636385707&lt;br /&gt;89636385755&lt;br /&gt;89636385675&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;$73747589$&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89629911485&lt;br /&gt;89629911932&lt;br /&gt;89629911658&lt;br /&gt;89629910152&lt;br /&gt;89629910824&lt;br /&gt;89629910747&lt;br /&gt;89629910275&lt;br /&gt;89629909846&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;10200000000000003&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89057635571&lt;br /&gt;89055280410&lt;br /&gt;89055280241&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;$73747589$&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;89055282108&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b&gt;^77723094^&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html" style="color: orange;"&gt;New Russian SMS ransomware In-the-Wild&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html" style="color: orange;"&gt;SMS Ransomware porn template update&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-1774225821993849881?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/1774225821993849881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1774225821993849881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1774225821993849881'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/09/campaign-to-disseminate-russian.html' title='Campaign to disseminate russian ransomware'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIBYViizOsI/AAAAAAAAAW0/zjrSUKQeM0E/s72-c/MI_ransom-russian.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5636481213005263129</id><published>2010-08-30T20:05:00.000-07:00</published><updated>2010-08-30T20:05:09.805-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>AntiSpy Safeguard with new social engineering approach</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;b&gt;AntiSpy Safeguard &lt;/b&gt;is a new rogue that is In-the-Wild and that its spread is new coverage of using deception in a video shown and a false report in the style of the services offered by &lt;a href="http://www.virustotal.com/" style="color: orange;"&gt;VirusTotal&lt;/a&gt; or &lt;span style="color: orange;"&gt;Virscan&lt;/span&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THxwgst9gEI/AAAAAAAAAWk/TpU-QI-dh60/s1600/MI_rogue-video.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="155" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THxwgst9gEI/AAAAAAAAAWk/TpU-QI-dh60/s400/MI_rogue-video.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The following image belongs to the inicial interface that is displayed in the first instance on a system infected by this rogue.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THxwJeQRoaI/AAAAAAAAAWU/oR0xJ9yvbpc/s1600/MI_rogue.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THxwJeQRoaI/AAAAAAAAAWU/oR0xJ9yvbpc/s400/MI_rogue.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;To read the full report&lt;a href="http://malwareint.blogspot.com/2010/08/fakeav-via-new-strategy-of-deception.html"&gt; &lt;span style="color: orange;"&gt;MalwareIntelligence blog&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-v.html" style="color: orange;"&gt;Litter Korean rogue lurking V&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5636481213005263129?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5636481213005263129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/antispy-safeguard-with-new-social.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5636481213005263129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5636481213005263129'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/antispy-safeguard-with-new-social.html' title='AntiSpy Safeguard with new social engineering approach'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THxwgst9gEI/AAAAAAAAAWk/TpU-QI-dh60/s72-c/MI_rogue-video.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-7009777865681711493</id><published>2010-08-28T19:01:00.000-07:00</published><updated>2010-08-28T19:01:28.306-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Litter Korean rogue lurking V</title><content type='html'>&lt;div style="text-align: justify;"&gt;Another piece of rogue from Korea and belonging to the family of &lt;b&gt;PrivacyKeep&lt;/b&gt;, &lt;b&gt;PrivacyCorp&lt;/b&gt; and &lt;b&gt;PCScan&lt;/b&gt;.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-GsdlCxI/AAAAAAAAAVc/okzYmEgJjK8/s1600/MI_pi.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;ProtectInfo&lt;/b&gt;&lt;br /&gt;protectinfo.co.kr - &lt;b&gt;114.108.168.8&lt;/b&gt; - DACOM-NET LG DACOM&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-GsdlCxI/AAAAAAAAAVc/okzYmEgJjK8/s1600/MI_pi.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-GsdlCxI/AAAAAAAAAVc/okzYmEgJjK8/s400/MI_pi.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The IP address also resolves the following domains:&lt;br /&gt;ad-clear.com&lt;br /&gt;privacycop.co.kr&lt;br /&gt;privacykeep.co.kr&lt;br /&gt;protectinfo.co.kr&lt;br /&gt;&lt;br /&gt;&lt;b&gt;protectinfo_home.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=52c8cbdaf314adaeeb58f3f4184884203e7cf9cb52545367cf7205c2661dfe4a-1282259983" style="color: orange;"&gt;a48e62c64f68a2b32dc601efffa2973d&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;update.protectinfo.co.kr/instchk.php&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;226&lt;br /&gt;[COUNTER]&lt;br /&gt;NUM=6&lt;br /&gt;&lt;br /&gt;[CHECK1]&lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=............&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=............&lt;br /&gt;&lt;br /&gt;[CHECK2]&lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=PrivacyCheck&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=.......... ....&lt;br /&gt;&lt;br /&gt;[CHECK3]&lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=............&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=............&lt;br /&gt;&lt;br /&gt;[CHECK4]&lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=............&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=............&lt;br /&gt;&lt;br /&gt;[CHECK5]&lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=..........&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=..........&lt;br /&gt;&lt;br /&gt;[CHECK6] &lt;br /&gt;HKEY=HKLM&lt;br /&gt;REGPATH=privacykeep&lt;br /&gt;REGNAME=DisplayName&lt;br /&gt;REGVALUE=............&lt;br /&gt;&lt;br /&gt;[HISTORYREG]&lt;br /&gt;PATH="............" &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;protectinfo.co.kr/app_linkage/app_install.php?addr=000C29CA888C&amp;amp;ptn=infocode0067&lt;br /&gt;protectinfo.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C &lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;3d &lt;br /&gt;payed=0&lt;br /&gt;pw_usr=&lt;br /&gt;pw_sup=1470&lt;br /&gt;hp1=&lt;br /&gt;hp2=&lt;br /&gt;hp3=&lt;br /&gt;small=300&lt;br /&gt;big=300&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;log.adsence.co.kr/logexp.php?aid=protectinfo&amp;amp;pid=infocode0067&amp;amp;kind=inst &lt;br /&gt;file.protectinfo.co.kr/update.php&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;protectinfo.exe=0.325&lt;br /&gt;pnfoupdater.exe=0.113&lt;br /&gt;pnfohk.dll=0.110&lt;br /&gt;pnfouninst.exe=0.1&lt;br /&gt;pnfowcher.exe=0.116&lt;br /&gt;pnfopopd.dll=0.1&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;protectinfo.co.kr/app_linkage/app_boot.php?ver=.0.398&lt;br /&gt;protectinfo.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C&lt;br /&gt;protectinfo.co.kr/settlement/paysys/mobile/Deliver.php&lt;br /&gt;protectinfo.co.kr/settlement/paysys/pbill/Deliver.php&lt;br /&gt;protectinfo.co.kr/settlement/paysys/ars/Deliver.php&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-5DgXRLI/AAAAAAAAAVk/C2NmKAPcMSA/s1600/MI_protectinfo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="220" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-5DgXRLI/AAAAAAAAAVk/C2NmKAPcMSA/s400/MI_protectinfo.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Uninstall from Program Files&lt;br /&gt;Running updated antivirus&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;&lt;/span&gt;&lt;span style="color: orange;"&gt;&lt;/span&gt; &lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-iv.html" style="color: orange;"&gt;Litter Korean rogue lurking IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html" style="color: orange;"&gt;Litter Korean rogue lurking III&lt;/a&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html" style="color: orange;"&gt;Litter Korean rogue lurking II&lt;/a&gt; &lt;/span&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html"&gt;&lt;span style="color: orange;"&gt;Litter Korean rogue lurking I&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-7009777865681711493?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/7009777865681711493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-v.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7009777865681711493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7009777865681711493'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-v.html' title='Litter Korean rogue lurking V'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THm-GsdlCxI/AAAAAAAAAVc/okzYmEgJjK8/s72-c/MI_pi.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5550030192177359431</id><published>2010-08-22T08:38:00.000-07:00</published><updated>2010-08-22T08:38:00.093-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Litter Korean rogue lurking IV</title><content type='html'>&lt;div style="text-align: justify;"&gt;Korean rogue fourth part of the "litter" that haunts the past few days looking for potential victims caught in Korea. At times the rogue that spread can have an option to change the language, so that coverage is much wider infection, however, in this case, it's directed at specific populations rogue.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THCcMAk5IxI/AAAAAAAAAVE/i-aimwncf30/s1600/MI_pc.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;PrivacyCorp&lt;/b&gt;&lt;br /&gt;privacycop.co.kr - &lt;b&gt;114.108.168.8&lt;/b&gt; - DACOM-NET LG DACOM&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THCcMAk5IxI/AAAAAAAAAVE/i-aimwncf30/s1600/MI_pc.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="143" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THCcMAk5IxI/AAAAAAAAAVE/i-aimwncf30/s400/MI_pc.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The IP is also the following domains:&lt;br /&gt;ad-clear.com&lt;br /&gt;info-dr.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;privacycop_setup.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=b207105421b1a94021572970ec69d4e7649a5de53f5aed856f53de8148a25deb-1282088693" style="color: orange;"&gt;8362c089bc4f7932dc885e23044cb2f6&lt;/a&gt;)&lt;br /&gt;&lt;b&gt;privacy_mediccop.exe&lt;/b&gt; (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=b6f02a469db1d6938bbc31a8cbfa83d5cef802d7f7accfdb7ce48912c6c136b5-1281974806" style="color: orange;"&gt;46f2a84d7217a5ca56208ea0b13c6f52&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The circuit is part rogue criminal systems led by members who pay a percentage of money for each installation of the threat spread. This case is no exception. The rogue reports successful installation immediately after infection.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THCcwcJj0XI/AAAAAAAAAVM/8ZaG5gxLa2I/s1600/MI_pc-scan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;privacycop.co.kr/app_linkage/app_install.php?addr=000C29CA888C&amp;amp;ptn=home&lt;br /&gt;log.adsence.co.kr/logexp.php?aid=privacycop&amp;amp;pid=home&amp;amp;kind=inst&lt;br /&gt;privacycop.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C &lt;br /&gt;3e &lt;br /&gt;payed=0&lt;br /&gt;pw_usr=&lt;br /&gt;pw_sup=1470&lt;br /&gt;hp1=&lt;br /&gt;hp2=&lt;br /&gt;hp3=&lt;br /&gt;small=300&lt;br /&gt;big=3660&lt;br /&gt;&lt;br /&gt;file.privacycop.co.kr/update.php &lt;br /&gt;6d &lt;br /&gt;privacycop.exe=0.328&lt;br /&gt;pvcupdater.exe=0.112&lt;br /&gt;pvchk.dll=0.1&lt;br /&gt;pvcuninst.exe=0.1&lt;br /&gt;pvcwcher.exe=0.112&lt;br /&gt;pvcpopd.dll=0.1&lt;br /&gt;&lt;br /&gt;privacycop.co.kr/app_linkage/app_boot.php?ver=.0.4.5.3 &lt;br /&gt;privacycop.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THCcwcJj0XI/AAAAAAAAAVM/8ZaG5gxLa2I/s1600/MI_pc-scan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THCcwcJj0XI/AAAAAAAAAVM/8ZaG5gxLa2I/s400/MI_pc-scan.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Terminate the processes called &lt;b&gt;privacycop.exe&lt;/b&gt; and &lt;b&gt;pvcwcher.exe&lt;/b&gt;. You can use the &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" style="color: orange;"&gt;ProcessExplorer&lt;/a&gt; to view and terminate processes.&lt;br /&gt;&lt;br /&gt;Uninstall from Program Files&lt;br /&gt;Running updated antivirus&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="color: orange;"&gt;&lt;/span&gt;&lt;span style="color: orange;"&gt;&lt;/span&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html" style="color: orange;"&gt;Litter Korean rogue lurking III&lt;/a&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html" style="color: orange;"&gt;Litter Korean rogue lurking II&lt;/a&gt; &lt;/span&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html"&gt;&lt;span style="color: orange;"&gt;Litter Korean rogue lurking I&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5550030192177359431?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5550030192177359431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-iv.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5550030192177359431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5550030192177359431'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-iv.html' title='Litter Korean rogue lurking IV'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THCcMAk5IxI/AAAAAAAAAVE/i-aimwncf30/s72-c/MI_pc.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-4767914483265123722</id><published>2010-08-22T06:16:00.000-07:00</published><updated>2010-08-22T06:16:00.886-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Litter Korean rogue lurking III</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THBCQ-UXTlI/AAAAAAAAAU0/biYotlVKvlQ/s1600/MI_PCscaner.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THBCbgWhN2I/AAAAAAAAAU8/Y-p8hvfQopg/s1600/MI_PCScan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;PCScan&lt;/b&gt; is another rogue Koreans that have appeared in recent days, in addition to the two previously showed.&lt;/div&gt;&lt;br /&gt;pcscan.kr - &lt;b&gt;114.108.129.233&lt;/b&gt; - DACOM-NET LG DACOM&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THBCbgWhN2I/AAAAAAAAAU8/Y-p8hvfQopg/s1600/MI_PCScan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="202" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THBCbgWhN2I/AAAAAAAAAU8/Y-p8hvfQopg/s400/MI_PCScan.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;The IP also resolves the following domains:&lt;br /&gt;eroza.net&lt;br /&gt;master.to84.net&lt;br /&gt;to84.net&lt;br /&gt;www.tvbaro.net&lt;br /&gt;&lt;br /&gt;Setup.exe (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=b0c9c02ae7f6800ab8aa2a83f25ac2c6ce301c16eb6f69036d83bd29a9a3625f-1282037567" style="color: orange;"&gt;a85900759318ea66dc94ba789aae2cfe&lt;/a&gt;)&lt;br /&gt;PCScan.exe (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=8e6bee10c71e38d2659509cbe7ab0ae8605f0e4d86c47e2362cf097b371a3618-1280882953" style="color: orange;"&gt;665b846b82d959843744d9d3a7b39bdc&lt;/a&gt;)&lt;br /&gt;PCScanMon.exe (&lt;span style="color: orange;"&gt;01cdb8f8955a4df6eebb1aca04d6a43c&lt;/span&gt;)&lt;br /&gt;Uninstall.exe (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=4ba6e7ddec920ae9a408becef3a6a03b8fe94ce227654058208a49a0692570dd-1282074848" style="color: orange;"&gt;76cd1340bded9d96050df30999f6274d&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Unistaller.exe&lt;/b&gt; file simulates the uninstaller antivirus program assumes, however, no effect arises because it’s false.&lt;/div&gt;&lt;br /&gt;Check the following pages:&lt;br /&gt;pcscan.kr/request/module_setup.php?p=PCScan&amp;amp;a=type1 &lt;br /&gt;pcscan.kr/request/License.txt&lt;br /&gt;pcscan.kr/down/install.exe&lt;br /&gt;down.elineguide.com/down/install.exe&lt;br /&gt;&lt;br /&gt;pcscan.kr/down/files.php?strMode=setup&amp;amp;strID=PCScan&amp;amp;arg=type1&amp;amp;strSite=&amp;amp;strPC=000c29ca888c &lt;br /&gt;pcscan.kr/down/PCScan.exe&lt;br /&gt;pcscan.kr/down/PCScanMon.exe&lt;br /&gt;pcscan.kr/down/Uninstall.exe&lt;br /&gt;pcscan.kr/down/PCScanControl.dll&lt;br /&gt;&lt;br /&gt;pcscan.kr/value.php?strMode=setup&amp;amp;strID=PCScan&amp;amp;arg=type1&amp;amp;strSite=&amp;amp;strPC=000c29ca888c&amp;amp;url=&lt;br /&gt;pcscan.kr/settle.php?strID=PCScan&amp;amp;arg=type1&amp;amp;strPC=000c29ca888c&amp;amp;strSite=pcscan.kr&lt;br /&gt;pcscan.kr/bill_danal/bill_home/with_bill.php?strID=PCScan&amp;amp;arg=type1&amp;amp;strPC=000c29ca888c&amp;amp;strSite=pcscan.kr&lt;br /&gt;pcscan.kr/consultation.php&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THBCQ-UXTlI/AAAAAAAAAU0/biYotlVKvlQ/s1600/MI_PCscaner.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="337" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THBCQ-UXTlI/AAAAAAAAAU0/biYotlVKvlQ/s400/MI_PCscaner.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasure&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Terminate the processes called PCScan.exe. You can use the &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" style="color: orange;"&gt;ProcessExplorer&lt;/a&gt; to view and terminate processes.&lt;br /&gt;&lt;br /&gt;Remove PCScan folder (which houses six files) located in C:\Program Files\pcscan\&lt;br /&gt;&lt;br /&gt;Delete the system registry pcscan key from HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run, which refers to "C:\Program Files\pcscan\pcscan.exe". You can use the &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" style="color: orange;"&gt;Autoruns&lt;/a&gt; to view and delete the key.&lt;br /&gt;&lt;br /&gt;Delete the desktop shortcut.&lt;br /&gt;&lt;br /&gt;Running updated antivirus&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html" style="color: orange;"&gt;Litter Korean rogue lurking II&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html" style="color: orange;"&gt;Litter Korean rogue lurking I&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-4767914483265123722?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/4767914483265123722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-iii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/4767914483265123722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/4767914483265123722'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-iii.html' title='Litter Korean rogue lurking III'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THBCbgWhN2I/AAAAAAAAAU8/Y-p8hvfQopg/s72-c/MI_PCScan.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6799921658871043568</id><published>2010-08-21T12:50:00.000-07:00</published><updated>2010-08-21T12:50:21.134-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Litter Korean rogue lurking II</title><content type='html'>&lt;div style="color: black;"&gt;Se trata de otro rogue perteneciente a la camada que actualmente se encuentra al acecho&lt;b&gt;. &lt;/b&gt;Su nombre es &lt;b&gt;PC Boan Plus&lt;/b&gt;.&lt;br /&gt;&lt;/div&gt;pcboanplus.com - &lt;b&gt;222.122.84.56&lt;/b&gt; - KORNET KOREA TELECOM&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAk9Bw12_I/AAAAAAAAAUc/n9Z_IMwzzbc/s1600/MI_PCboan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAk9Bw12_I/AAAAAAAAAUc/n9Z_IMwzzbc/s400/MI_PCboan.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;Domains that resolve to the same IP:&lt;br /&gt;postmaster.8282tv.co.kr&lt;br /&gt;pspd.org&lt;br /&gt;&lt;br /&gt;&lt;b&gt;PcBoanPlus2SetupH.exe&lt;/b&gt; (0ab2cc07373a4b88a0084f12ae63f54f)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THAlRo25DcI/AAAAAAAAAUk/17-bb26KXlE/s1600/MI_PCBoan-scan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="271" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THAlRo25DcI/AAAAAAAAAUk/17-bb26KXlE/s400/MI_PCBoan-scan.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This  rogue report a system of affiliates Pay-per-Install that resolves the  domain to an IP address corresponding to the ISP "&lt;b&gt;KRNIC&lt;/b&gt;".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;b&gt;211.33.123.40&lt;/b&gt;/pcboanplus/install.php?mac=000C29CA888C&amp;amp;partner=PcBoanPlus&amp;amp;ver= &lt;br /&gt;&lt;br /&gt;file.pcboanPlus.com/app/updater/PcBoanPlus2Up.exe&lt;br /&gt;file.pcboanplus.com/app/Client/PcBoanplus2.exe&lt;br /&gt;pcboanplus.com/app/badinfo.php?Vn=2005010100&amp;amp;Kind=comp&lt;br /&gt;&lt;br /&gt;s223.pc-korea.net/badlist/2010080700_badfile.dat&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THAmvT3KD6I/AAAAAAAAAUs/v0DCEAF6SNs/s1600/MI_PC-korea.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="161" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THAmvT3KD6I/AAAAAAAAAUs/v0DCEAF6SNs/s400/MI_PC-korea.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasure&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Uninstall from Program Files&lt;br /&gt;Running updated antivirus&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt; &lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html"&gt;&lt;span style="color: orange;"&gt;Litter Korean rogue lurking I&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwareint.blogspot.com/2010/08/pirated-edition-affiliate-program-pay.html" style="color: orange;"&gt;Pirated Edition. Affiliate program Pay-per-Install&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwareint.blogspot.com/2010/08/pay-per-install-through-viva-installs.html" style="color: orange;"&gt;Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI&amp;nbsp;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6799921658871043568?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6799921658871043568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6799921658871043568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6799921658871043568'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-ii.html' title='Litter Korean rogue lurking II'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAk9Bw12_I/AAAAAAAAAUc/n9Z_IMwzzbc/s72-c/MI_PCboan.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5518630639272805178</id><published>2010-08-21T12:39:00.000-07:00</published><updated>2010-08-21T12:39:22.832-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Litter Korean rogue lurking I</title><content type='html'>&lt;div style="text-align: justify;"&gt;Language issues are not limited to developers of malicious code and the objectives of the criminals are far beyond any border, and although it is usually the largest flow of varieties are in English and, to a lesser extent Russian every now and then the guns are aimed at specific audiences, as in this case: Korean rogue.&lt;/div&gt;&lt;br /&gt;&lt;div style="color: black;"&gt;&lt;b&gt;MegaVaccine&lt;/b&gt;&lt;/div&gt;megavaccine.com - &lt;b&gt;218.146.255.151&lt;/b&gt; - KORNET KOREA TELECOM&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAiWprPBpI/AAAAAAAAAUM/0TJhuD7rFlM/s1600/MI_MV-korea.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAiWprPBpI/AAAAAAAAAUM/0TJhuD7rFlM/s400/MI_MV-korea.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THAiSxfRf9I/AAAAAAAAAUE/3CC87DVG1vU/s1600/MI_pkwow.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;The IP is also the following domains:&lt;br /&gt;goodprivacy.co.kr&lt;br /&gt;megavaccine.com&lt;br /&gt;pc-privacy.co.kr&lt;br /&gt;pc-up.co.kr&lt;br /&gt;pcsweeper.co.kr&lt;br /&gt;pctool.co.kr&lt;br /&gt;privacyboan.com&lt;br /&gt;privacyq.com&lt;br /&gt;rprotect.co.kr&lt;br /&gt;uprivacy.net&lt;br /&gt;wowprotect.co.kr&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THAiSxfRf9I/AAAAAAAAAUE/3CC87DVG1vU/s1600/MI_pkwow.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="88" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/THAiSxfRf9I/AAAAAAAAAUE/3CC87DVG1vU/s400/MI_pkwow.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;megavaccine_setup.exe (&lt;a href="http://www.virustotal.com/file-scan/report.html?id=5b4f53218fb3da9fe188193ed46d0fd52b5050adb0d5b2a1933fd92a9adf6fa7-1282310433" style="color: orange;"&gt;2234041b04e072aa7585209fa66e8550&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;down.megavaccine.com/autoupdate/MegaVaccine/MVaccine.exe&lt;br /&gt;down.megavaccine.com/Update_db/addb.dat&lt;br /&gt;down.megavaccine.com/Update_db/adsub.dat&lt;br /&gt;down.megavaccine.com/Update_db/adtc.dat&lt;br /&gt;down.megavaccine.com/Update_db/avmon.dat&lt;br /&gt;down.megavaccine.com/Update_db/inter.dll&lt;br /&gt;down.megavaccine.com/Update_db/pwdb.dat&lt;br /&gt;down.megavaccine.com/Update_db/vsdb.dat&lt;br /&gt;down.megavaccine.com/Update_info/2010081900-00-.txt&lt;br /&gt;down.megavaccine.com/Update_ini/MegaVaccine/autoupdate.ini&lt;br /&gt;down.megavaccine.com/app/weboard.html&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THAiYyETHNI/AAAAAAAAAUU/ocpy3RWPa5s/s1600/MI_MV-korea-scan.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="255" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/THAiYyETHNI/AAAAAAAAAUU/ocpy3RWPa5s/s400/MI_MV-korea-scan.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAiWprPBpI/AAAAAAAAAUM/0TJhuD7rFlM/s1600/MI_MV-korea.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasure&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Uninstall from Program Files&lt;br /&gt;Running updated antivirus&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html" style="color: orange;"&gt;PC Defender Antivirus rogue update system registry&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html" style="color: orange;"&gt;Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5518630639272805178?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5518630639272805178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5518630639272805178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5518630639272805178'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/litter-korean-rogue-lurking-i.html' title='Litter Korean rogue lurking I'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/THAiWprPBpI/AAAAAAAAAUM/0TJhuD7rFlM/s72-c/MI_MV-korea.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-1873281739609966704</id><published>2010-08-15T18:07:00.000-07:00</published><updated>2010-08-15T18:07:20.566-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New Russian SMS ransomware In-the-Wild</title><content type='html'>&lt;div style="text-align: justify;"&gt;The development of malware designed to block access to the operating system is in full expansion. Despite being at present a very different generation of &lt;b&gt;ransomware &lt;/b&gt;the first generations where, using cryptovirology, literally kidnapped by encrypting user files and requesting a financial compensation in exchange for the release key, the concept and goal has not changed.&lt;br /&gt;&lt;br /&gt;In this case, it’s a new variant of &lt;b&gt;SMS ransomware&lt;/b&gt; blocking access to the operating system screen showing an alleged safety report in which reference is an infection caused by a variant of trojan recruits zombie botnets for &lt;b&gt;ZeuS&lt;/b&gt; is actually false.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGiOCuLtaII/AAAAAAAAATc/4U6uSoYWqwY/s1600/MI_ransom-blocker.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="315" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGiOCuLtaII/AAAAAAAAATc/4U6uSoYWqwY/s400/MI_ransom-blocker.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The brief report is in Russian language with which it follows that the objectives of malware are the users of that country. However, the spread of the threat has no boundaries and no language limitations.&lt;br /&gt;&lt;br /&gt;According to the text, to get a key to unlocking it's necessary to send a message such as SMS to &lt;b&gt;4161&lt;/b&gt; with the message&lt;b&gt; 2AV112239&lt;/b&gt;. This set of alphanumeric characters isn’t the only one who can show, as it has a list that is displayed at random. The list consists of the following springs:&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;2AV166522, 2AV288764, 2AV222419, 2AV288888, 2AV266555, 2AV119999, 2AV121436, 2AV178477, 2AV166522, 2AV111199, 2AV187211, 2AV133211, 2AV111223, 2AV243562, 2AV211246, 2AV244533, 2AV277631, 2AV233884, 2AV242665, 2AV233211, 2AV288599, 2AV299884, 2AV286442, 2AV248864, 2AV222464, 2AV288434, 2AV265543, 2AV211278, 2AV299977, 2AV165431, 2AV131313, 2AV132218, 2AV155543, 2AV166666, 2AV186443, 2AV155422, 2AV198775, 2AV144366, 2AV199797, 2AV197797, 2AV177979, 2AV166321, 2AV111229, 2AV155322, 2AV187532, 2AV112239, 2AV164554, 2AV134274, 2AV153221, 2AV311111, 2AV311112, 2AV311113, 2AV311114, 2AV311115, 2AV311116, 2AV311117, 2AV311118, 2AV311119, 2AV311120, 2AV311121, 2AV311123, 2AV311124, 2AV311125, 2AV311126, 2AV311127, 2AV311128, 2AV311129, 2AV311130, 2AV311131, 2AV311132, 2AV311133, 2AV311134, 2AV311135, 2AV311136, 2AV311137, 2AV311138, 2AV311139, 2AV311140, 2AV311141, 2AV311142, 2AV311143, 2AV311144, 2AV311145, 2AV311146, 2AV311147, 2AV311148, 2AV311149, 2AV311150, 2AV311151, 2AV311152, 2AV311153, 2AV311154, 2AV311155, 2AV311156, 2AV311157, 2AV311158, 2AV311159, 2AV311160, 2AV311161, 2AV311162, 2AV311163, 2AV311164, 2AV311165, 2AV311166, 2AV311167, 2AV311168, 2AV311169, 2AV311170, 2AV311171, 2AV311172, 2AV311173, 2AV311174, 2AV311175, 2AV311176, 2AV311177, 2AV311178, 2AV311179&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;The malware disables the possibility to access the system in Safe Mode and access the following programs:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;TASKMGR.EXE&lt;/li&gt;&lt;li&gt;REGEDT32.EXE&lt;/li&gt;&lt;li&gt;MSCONFIG.EXE&lt;/li&gt;&lt;li&gt;EXPLORER.EXE&lt;/li&gt;&lt;li&gt;TEXPL.EXE&lt;/li&gt;&lt;li&gt;ANVIR.EXE &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasure&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Unlock using the following key:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Environ&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;Click the first button and press the &lt;b&gt;Enter&lt;/b&gt; key.&lt;br /&gt;Restart the system.&lt;br /&gt;Delete the registry key from ctfmon.exe.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGiOJ4sXKHI/AAAAAAAAATk/4vB1U23aJwk/s1600/MI_regedit.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="67" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGiOJ4sXKHI/AAAAAAAAATk/4vB1U23aJwk/s400/MI_regedit.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Run an updated antivirus.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-1873281739609966704?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/1873281739609966704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1873281739609966704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/1873281739609966704'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/new-russian-sms-ransomware-in-wild.html' title='New Russian SMS ransomware In-the-Wild'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGiOCuLtaII/AAAAAAAAATc/4U6uSoYWqwY/s72-c/MI_ransom-blocker.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5843158769335164931</id><published>2010-08-11T12:18:00.000-07:00</published><updated>2010-08-11T12:18:14.065-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>PC Defender Antivirus rogue update system registry</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGL04JSl3FI/AAAAAAAAASk/in6ZuUmiP_w/s1600/MI_pcdav-act.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The criminals who are behind the development of &lt;b&gt;PC Defender Antivirus&lt;/b&gt; rogue in the last few hours have updated the registration system for the false application.&lt;br /&gt;&lt;br /&gt;The record in the first version was to send a text message SMS rate telephone number located in Russia, while this new version requests a serial number (supposedly under the hardware-locked system) generated using as part of a activation key.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGL04JSl3FI/AAAAAAAAASk/in6ZuUmiP_w/s1600/MI_pcdav-act.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="302" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGL04JSl3FI/AAAAAAAAASk/in6ZuUmiP_w/s400/MI_pcdav-act.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;It also adds a button (Buy) that redirects to a form hosted on &lt;i&gt;Plimus&lt;/i&gt;, and updated the malware into English. The first version was only in Russian.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGL1EHyyJ5I/AAAAAAAAASs/I0rJMymWGOw/s1600/MI_en.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="217" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGL1EHyyJ5I/AAAAAAAAASs/I0rJMymWGOw/s400/MI_en.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This action makes it quite evident that behind the spread of these threats, lies across an organization intended to develop malware to accommodate an underground economy that feeds, increasingly, fraudulent methods.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5843158769335164931?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5843158769335164931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5843158769335164931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5843158769335164931'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/pc-defender-antivirus-rogue-update.html' title='PC Defender Antivirus rogue update system registry'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGL04JSl3FI/AAAAAAAAASk/in6ZuUmiP_w/s72-c/MI_pcdav-act.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2169049517154662498</id><published>2010-08-11T11:07:00.000-07:00</published><updated>2010-08-11T11:32:50.625-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;b&gt;Pay-per-Install&lt;/b&gt; is one of the business models by which an &lt;b&gt;affiliate system&lt;/b&gt; provides a set of "clients" one or more malicious code, paying each a percentage of money as a commission for each installation the malicious application successful.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Phoenix Exploit's Kit&lt;/b&gt; is a crimeware by which intelligence is done collecting statistical information related to each of the infected computers. You enter through an access panel via the http protocol as we see in the screenshot.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLirliq6VI/AAAAAAAAARs/JxpwPrkBnPA/s1600/MI_login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="238" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLirliq6VI/AAAAAAAAARs/JxpwPrkBnPA/s400/MI_login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLi5CccdlI/AAAAAAAAAR0/906aUzYdpzI/s1600/MI_pcdav.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;PC Defender Antivirus&lt;/b&gt; is a rogue Russian origin whose spread is being made through Phoenix Exploit's Kit, reporting at the same time to an affiliate system that records the installation of each downloaded copy.&lt;br /&gt;&lt;br /&gt;In addition to collaborating with the criminal circuit feeding back the fraudulent business through Pay-per-Install, the rogue has the grain of usual business whereby it’s intended that the fraudulent application is purchased, also via the web, this action involving form information stored somewhere confidential credit card. The cost of the rogue is &lt;b&gt;USD 59.95&lt;/b&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLi5CccdlI/AAAAAAAAAR0/906aUzYdpzI/s1600/MI_pcdav.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="303" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLi5CccdlI/AAAAAAAAAR0/906aUzYdpzI/s400/MI_pcdav.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjDc4xLGI/AAAAAAAAAR8/bq6nI5a-bh8/s1600/MI-pcap.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Through Phoenix Exploit's Kit spreads a trojan downloader called &lt;b&gt;exe.exe&lt;/b&gt;, in this case MD5 e49be7ef82250a36cf7410004ac3d69c that, after it establishes a connection to fordkaksosat.info (&lt;b&gt;193.105.207.45&lt;/b&gt; - &lt;b&gt;AS50793&lt;/b&gt; "&lt;b&gt;ALFAHOSTNET&lt;/b&gt;") from which it downloads and executes the rogue (&lt;b&gt;PCDefenderSilentSetup.msi &lt;/b&gt;- ecff63c1f983858dfd7fb926738cb478).&lt;br /&gt;&lt;br /&gt;In this instance, the rogue is reported to the affiliate system to load the information on successful installation through &lt;b&gt;count_installs.php&lt;/b&gt; file, and begins a malware scan issuing alerts about alleged attempts to connect infections and also false. This activity is usual in this type of malware to be one of their employers.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjDc4xLGI/AAAAAAAAAR8/bq6nI5a-bh8/s1600/MI-pcap.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjDc4xLGI/AAAAAAAAAR8/bq6nI5a-bh8/s400/MI-pcap.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjLYVkSoI/AAAAAAAAASE/wg9mK1-xatc/s1600/MI_PCDAV-infection.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjLYVkSoI/AAAAAAAAASE/wg9mK1-xatc/s400/MI_PCDAV-infection.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The release system for the alleged security application is similar to that used by some families of ransomware through the business model that involves sending a text message SMS to a specific type of phone number.&lt;br /&gt;&lt;br /&gt;In this case, the information should be sent to the number &lt;b&gt;5711000002209&lt;/b&gt; with the message &lt;b&gt;6681&lt;/b&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjYaA16mI/AAAAAAAAASM/ZzJ1IzxV2Go/s1600/MI_PCDAV-SMS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="301" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjYaA16mI/AAAAAAAAASM/ZzJ1IzxV2Go/s400/MI_PCDAV-SMS.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The threat has a timer which generates a false statement &lt;b&gt;Blue Screen of Death&lt;/b&gt; (&lt;b&gt;BSoD)&lt;/b&gt;, in which shows the incentive to record the program, exerting a fear (psychological warfare) on the user that after reading this information might think register/buy what you think, this is a real antivirus solution.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjmqNGjZI/AAAAAAAAASU/VUg8yQxHJdY/s1600/MI_BSoD.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLjmqNGjZI/AAAAAAAAASU/VUg8yQxHJdY/s400/MI_BSoD.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLju6mT3GI/AAAAAAAAASc/-RIwOO3fLfs/s1600/MI_pcdav-files.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Terminate the processes called &lt;b&gt;prockill32.exe&lt;/b&gt;, &lt;b&gt;proccheck.exe&lt;/b&gt; and &lt;b&gt;rundelay.exe&lt;/b&gt;. You can use the &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" style="color: orange;"&gt;ProcessExplorer&lt;/a&gt; to view and terminate processes.&lt;br /&gt;&lt;br /&gt;Remove PC Defender folder (which houses six files) located in &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Program Files\Def Group\&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLju6mT3GI/AAAAAAAAASc/-RIwOO3fLfs/s1600/MI_pcdav-files.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TGLju6mT3GI/AAAAAAAAASc/-RIwOO3fLfs/s320/MI_pcdav-files.png" /&gt;&lt;/a&gt;&lt;/div&gt;Delete the system registry PC Defender key from &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run&lt;/span&gt;, which refers to &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;c:\program files\def group\PC Defender\pcdef.exe&lt;/span&gt;. You can use the &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" style="color: orange;"&gt;Autoruns&lt;/a&gt; to view and delete the key.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related Information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;Copyright violation: copyrighted content detected&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/08/campaign-infection-through-phoenix.html" style="color: orange;"&gt;Campaign infection through Phoenix Exploit's Pack&lt;/a&gt; &lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html" style="color: orange;"&gt;LockScreen. Your computer is infected by Spyware!!!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2169049517154662498?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2169049517154662498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2169049517154662498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2169049517154662498'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/08/phoenix-exploits-kit-and-pay-per.html' title='Phoenix Exploit&apos;s Kit and Pay-per-Install via PC Defender Antivirus'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGLirliq6VI/AAAAAAAAARs/JxpwPrkBnPA/s72-c/MI_login.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-3322604338235450514</id><published>2010-07-22T19:58:00.000-07:00</published><updated>2010-07-22T20:09:14.827-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>SMS Ransomware porn template update</title><content type='html'>&lt;div style="text-align: justify;"&gt;A new &lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;variant of ransomware type blocker that promotes pornographic sites&lt;/a&gt; is In-the-Wild, with the inner slightly modified. Basically you have changed the number to which the victim must send messages like SMS. Now the number is &lt;b&gt;86571252&lt;/b&gt; and the message remains the same: &lt;b&gt;6005&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Another change is in the location which holds the copy of the threat. In this case, the path is &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\Default User\Media\&lt;/span&gt; under the name &lt;b&gt;run32.exe&lt;/b&gt;. The first image shows the previous version, while the second corresponds to the new variant of the &lt;b&gt;SMS Ransomware&lt;/b&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDAiS9iuI/AAAAAAAAAQk/mATI_j_6RCM/s1600/MI_ransom-full.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDAiS9iuI/AAAAAAAAAQk/mATI_j_6RCM/s400/MI_ransom-full.png" width="400" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDNXBazcI/AAAAAAAAAQs/Sdk_vDbxQ94/s1600/MI_ransom-upd1..png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDNXBazcI/AAAAAAAAAQs/Sdk_vDbxQ94/s400/MI_ransom-upd1..png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDWEFfSYI/AAAAAAAAAQ0/Io5QQv-Idto/s1600/MI_ransom-update2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The ransomware is distributed, as in previous cases, through porn sites. This variant uses the same name as cover (flash_player.exe), its MD5 is &lt;b&gt;2e8f56ce39270e10f7082a35d13a735a&lt;/b&gt; and as I write this update has a detection rate average, &lt;a href="http://www.virustotal.com/analisis/fe504e0f8f6ae024159cfb7a9b7622db3d3919c297fe62939fbb9eda8f699b79-1279837077" style="color: orange;"&gt;12/42 being detected by antivirus engines&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDWEFfSYI/AAAAAAAAAQ0/Io5QQv-Idto/s1600/MI_ransom-update2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDWEFfSYI/AAAAAAAAAQ0/Io5QQv-Idto/s400/MI_ransom-update2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Identify and terminate the process called "&lt;b&gt;run32.exe&lt;/b&gt;." At this time ransomware window disappears.&lt;br /&gt;** The name of the process can also be &lt;b&gt;process32.exe&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;*** To kill the process you can use Task Manager or the native Windows application &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" style="color: orange;"&gt;ProcessExplorer&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Delete the following system information&lt;br /&gt;Registry:&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Module&lt;/span&gt;&lt;br /&gt;Value:&lt;br /&gt;AModule&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;"C:\Documents and Settings\Administrador\Media\run32.exe"&lt;/span&gt;&lt;br /&gt;*** You can also use &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" style="color: orange;"&gt;Autoruns&lt;/a&gt; application to view the record in an orderly manner.&lt;br /&gt;&lt;br /&gt;Folders:&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\Default User\Media&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media\run32.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media\rdb.bat&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites IV&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-3322604338235450514?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/3322604338235450514/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/3322604338235450514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/3322604338235450514'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/07/sms-ransomware-porn-template-update.html' title='SMS Ransomware porn template update'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEkDAiS9iuI/AAAAAAAAAQk/mATI_j_6RCM/s72-c/MI_ransom-full.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-9065872516394203771</id><published>2010-07-17T19:11:00.000-07:00</published><updated>2010-08-21T20:56:27.271-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New variant of ransomware through porn sites IV</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhHDCAR9I/AAAAAAAAAQE/dX9wqKfvr7Y/s1600/MI_new-ransom-block.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another variant of the family &lt;b&gt;ransomware&lt;/b&gt; of type blocker is In-the-Wild, using as cover for attacks to be the Flash Player installer via an executable file called &lt;a href="http://www.virustotal.com/analisis/4485e49d5d47e18cde6cb44e77c288aabb174d02855388c40f225bf21c26dea4-1279260582" style="color: orange;"&gt;&lt;b&gt;flash_player.exe&lt;/b&gt;&lt;/a&gt; and whose MD5 is &lt;b&gt;acf591ac5ad2a26bf348708dda174b33&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;This time is also related to a porn site that opens immediately after infecting the system. However, unlike past versions, the window does not display an image block with conditional connotation.&amp;nbsp; &lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhHDCAR9I/AAAAAAAAAQE/dX9wqKfvr7Y/s1600/MI_new-ransom-block.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="287" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhHDCAR9I/AAAAAAAAAQE/dX9wqKfvr7Y/s400/MI_new-ransom-block.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhN1TO9OI/AAAAAAAAAQM/7Kea9mVFCx4/s1600/MI_new-ransom-block-2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As we see in the image, just simply presents the user requirements towards obtaining the necessary password to allow, in theory, to unlock the appearance of the annoying window, but does not occupy the whole desktop (also very common case in ransomware), the window stays malicious in the lower right of this, superimposed on any other window.&lt;/div&gt;&lt;br /&gt;In this case the user should send a short text message &lt;b&gt;SMS&lt;/b&gt; to &lt;b&gt;86577491&lt;/b&gt; with message &lt;b&gt;6005&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhN1TO9OI/AAAAAAAAAQM/7Kea9mVFCx4/s1600/MI_new-ransom-block-2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="287" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhN1TO9OI/AAAAAAAAAQM/7Kea9mVFCx4/s400/MI_new-ransom-block-2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhVd-qTlI/AAAAAAAAAQU/qNshN60r8hY/s1600/MI_ransom-full.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When the binary is executed through a simple sentence written in BAT, tells the malicious application that copies itself to &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media&lt;/span&gt; under the name &lt;b&gt;kasper_zaebal.exe&lt;/b&gt;, add a reference in Run registry key and adds information security area.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhVd-qTlI/AAAAAAAAAQU/qNshN60r8hY/s1600/MI_ransom-full.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhVd-qTlI/AAAAAAAAAQU/qNshN60r8hY/s400/MI_ransom-full.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Parallel open a browser session by redirecting traffic to the porn site that resolves &lt;b&gt;www.redtube.eu&lt;/b&gt; IP address &lt;b&gt;216.155.139.158&lt;/b&gt; (&lt;b&gt;AS20473 - CHOOPA&lt;/b&gt;), classified as malware server and C&amp;amp;C of some botnets.&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Enter the following code: &lt;b&gt;29543874&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;If you want to try a more "traditional" follow the steps below: &lt;br /&gt;&lt;br /&gt;Identify and terminate the process called "kasper_zaebal.exe." At this time ransomware window disappears.&lt;br /&gt;&lt;br /&gt;To kill the process you can use Task Manager or the native Windows application &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" style="color: orange;"&gt;ProcessExplorer&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Delete the following system information&lt;br /&gt;&lt;br /&gt;Registry: &lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Module&lt;/span&gt;&lt;br /&gt;Value: &lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;AModule&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;“%ALLUSERSPROFILE%\Media\kasper_zaebal.exe”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You can also use &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" style="color: orange;"&gt;Autoruns&lt;/a&gt; application to view the record in an orderly manner.&lt;br /&gt;&lt;br /&gt;Folders:&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media\kasper_zaebal.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media\rdb.ba&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://twitter.com/jorgemieres" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEJjsQv18QI/AAAAAAAAAQc/00l0WDs0VO0/s200/follow_tw.png" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&amp;nbsp; II&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-9065872516394203771?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/9065872516394203771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/9065872516394203771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/9065872516394203771'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/07/new-variant-of-ransomware-through-porn.html' title='New variant of ransomware through porn sites IV'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TEJhHDCAR9I/AAAAAAAAAQE/dX9wqKfvr7Y/s72-c/MI_new-ransom-block.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-951333893867334940</id><published>2010-06-20T10:54:00.000-07:00</published><updated>2010-06-20T10:57:02.244-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New variant of ransomware through porn sites III</title><content type='html'>&lt;div style="text-align: justify;"&gt;Another variant is ransomawre In-the-Wild. Like previous variants, it spreads through porn sites. The case presented &lt;b&gt;axporno.ru&lt;/b&gt; page uses a vector of propagation.&lt;br /&gt;&lt;br /&gt;When infecting the computer displays a window that overlaps any other, and by showing the information needed to theoretically unlock the system.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5STiWDVnI/AAAAAAAAALc/y824MuWCLPU/s1600/ransom.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5STiWDVnI/AAAAAAAAALc/y824MuWCLPU/s320/ransom.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SY24JPmI/AAAAAAAAALk/sj70lezzCwQ/s1600/ransom2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When you try to close the image is displayed in a new window that provides information on how to eliminate it. The maneuver, as is usual in the latest generation of ransomware type blocker, is to encourage the user to send a text message SMS rate to a certain number (&lt;b&gt;162772132&lt;/b&gt;) and certain information (&lt;b&gt;3381&lt;/b&gt;).&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SY24JPmI/AAAAAAAAALk/sj70lezzCwQ/s1600/ransom2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SY24JPmI/AAAAAAAAALk/sj70lezzCwQ/s320/ransom2.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SnGOFs3I/AAAAAAAAALs/_hhPOfFztGs/s1600/smscost.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Create files &lt;b&gt;sc.ini&lt;/b&gt; and &lt;b&gt;delself.bat&lt;/b&gt;, both housed in the System32 folder. The first stores information equivalent to the number of infection and route where the malware binary, while the second saves the information to remove some tracks.&lt;/div&gt;&lt;br /&gt;&lt;b&gt;sc.ini&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;600&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media\module.exe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;delself.bat&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;…&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;del C:\Documents and Settings\All Users\Media\module.exe&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;if exist C:\Documents and Settings\All Users\Media\module.exe goto try&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;del C:\WINDOWS\system32\sc.ini&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;del C:\WINDOWS\system32\delself.bat&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The malware uses the service &lt;b&gt;SmsCost&lt;/b&gt; (&lt;b&gt;smscost.ru&lt;/b&gt;) to provide information on the cost of the SMS message.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SnGOFs3I/AAAAAAAAALs/_hhPOfFztGs/s1600/smscost.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5SnGOFs3I/AAAAAAAAALs/_hhPOfFztGs/s320/smscost.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;In addition to promoting another page with sexually explicit material through which also spreads malware (&lt;b&gt;amporno.ru&lt;/b&gt;).&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Remove the "module" process through task manager (Ctrl + Alt + Del).&lt;br /&gt;Search and delete the following processes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;module.exe &lt;span style="font-size: x-small;"&gt;(MD5: 4D6C1F95ED90DDEE122FC749FCE1084E)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;sc.ini &lt;span style="font-size: x-small;"&gt;(&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;MD5: &lt;/span&gt;&lt;span style="font-size: x-small;"&gt;FEADA1AF5309D97A537D02DD6678E847)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;delself.bat&lt;span style="font-size: x-small;"&gt; (&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;MD5: &lt;/span&gt;&lt;span style="font-size: x-small;"&gt;E327DE8BC4BC1183CC9A60776717DA38)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;Delete the folder hosted on Media C:\Documents and Settings\All Users\Media&lt;br /&gt;&lt;br /&gt;Delete the following registry key:&lt;br /&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Module &amp;gt; c:\documents and settings\all users\media\module.exe&lt;br /&gt;&lt;br /&gt;Install an updated antivirus security program and perform a deep scan mode.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://www.blogger.com/goog_2000293822"&gt;New variant of ransomware  through porn sites&lt;/a&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html"&gt;  II &lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html"&gt;New  variant of ransomware through porn sites&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&amp;nbsp; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-951333893867334940?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/951333893867334940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/951333893867334940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/951333893867334940'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/06/new-variant-of-ransomware-through-porn.html' title='New variant of ransomware through porn sites III'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TB5STiWDVnI/AAAAAAAAALc/y824MuWCLPU/s72-c/ransom.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6653801651403867346</id><published>2010-05-04T04:26:00.000-07:00</published><updated>2010-07-17T17:16:54.491-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New variant of ransomware through porn sites II</title><content type='html'>&lt;div style="text-align: justify;"&gt;A new variant of this malware is In-the-Wild. It spreads through pornographic websites. When the user clicks on any of the images that presents the page to view the video course, an alert box warns about the need to install the Flash Player 10 application and offers the download of executable called &lt;b&gt;flash_player.exe course&lt;/b&gt; (&lt;a href="http://www.virustotal.com/analisis/9ce3b4f8b78146df14692b934919b6449227ec79e0e51e446d9f07aabad3415e-1272926932" style="color: orange;"&gt;f26c45393af03e80a40ea06aafb01c63&lt;/a&gt;).&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994Sz7XUiI/AAAAAAAAAJs/UMt39OyFLAQ/s1600/fake-flash.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994Sz7XUiI/AAAAAAAAAJs/UMt39OyFLAQ/s320/fake-flash.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S994Tj63bxI/AAAAAAAAAJ0/j1OdZwuwYPo/s1600/ransom-block.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Like the case previously presented in this blog, this is a ransomware that displays a window with pornographic content.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S994Tj63bxI/AAAAAAAAAJ0/j1OdZwuwYPo/s1600/ransom-block.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S994Tj63bxI/AAAAAAAAAJ0/j1OdZwuwYPo/s320/ransom-block.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994U5rnQjI/AAAAAAAAAJ8/bKmUQjs-z4g/s1600/traffic.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As usual in this type of malicious code in order to eliminate the annoying image, requests to send a text message SMS rate (&lt;b&gt;3381&lt;/b&gt;) to a specific phone number (&lt;b&gt;84234321&lt;/b&gt;)&lt;br /&gt;&lt;br /&gt;In addition, constantly opening a website with pornographic content is also hosted at IP address 77.247.179.176&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994U5rnQjI/AAAAAAAAAJ8/bKmUQjs-z4g/s1600/traffic.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994U5rnQjI/AAAAAAAAAJ8/bKmUQjs-z4g/s320/traffic.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Delete the following processes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;plugin.exe&lt;/li&gt;&lt;li&gt;watcher.exe&lt;/li&gt;&lt;/ul&gt;Delete the folder hosted on Media C:\Documents and Settings\All Users\Media&lt;br /&gt;&lt;br /&gt;Delete the following registry key:&lt;br /&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Module &amp;gt; c:\documents and settings\all users\media\plugin.exe&lt;br /&gt;&lt;br /&gt;Or unlock with the following code: &lt;b&gt;19282736&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994Sz7XUiI/AAAAAAAAAJs/UMt39OyFLAQ/s1600/fake-flash.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt; &lt;/a&gt;&lt;/div&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html"&gt;&lt;span style="color: orange;"&gt;Copyright violation: copyrighted content detected&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware  detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your  System Is Infected!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html" style="color: orange;"&gt;LockScreen. Your computer is infected by  Spyware!!!&lt;/a&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html" target="_blank"&gt; &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6653801651403867346?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6653801651403867346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6653801651403867346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6653801651403867346'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/05/new-variant-of-ransomware-through-porn.html' title='New variant of ransomware through porn sites II'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S994Sz7XUiI/AAAAAAAAAJs/UMt39OyFLAQ/s72-c/fake-flash.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6835788720123613275</id><published>2010-04-24T20:47:00.000-07:00</published><updated>2010-08-21T13:13:00.878-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='adware'/><title type='text'>Copyright violation: copyrighted content detected</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5NAWHPtI/AAAAAAAAAIk/VuofERnZFAk/s1600/copyright-violation.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;New &lt;b&gt;ransomaware&lt;/b&gt; In-the-Wild that under the excuse of being issued by an alleged entity that protects copyrights, tries to obtain money by deception strategy that seeks to "negotiate" with the victim to pay a fine.&lt;br /&gt;&lt;br /&gt;At the time of executing its payload, operating system crashes showing a window as shown below, in which "warned" of the alleged violation of the copyright in the computer to detect copyright material.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5NAWHPtI/AAAAAAAAAIk/VuofERnZFAk/s1600/copyright-violation.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5NAWHPtI/AAAAAAAAAIk/VuofERnZFAk/s320/copyright-violation.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5enV7AWI/AAAAAAAAAIs/XbvGGV1MCsw/s1600/wallpaper2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt; &lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The information presented on the screen can be displayed in ten languages: &lt;i&gt;English, Czech, Danish, Dutch, French, German, Italian, Portuguese, Slovak and Spanish&lt;/i&gt;. This feature shows the professional looking for the attackers because every translation is well done, which is achieved by outsourcing translation work.&lt;/div&gt;&lt;br /&gt;On occasion wallpaper set as the following image:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5enV7AWI/AAAAAAAAAIs/XbvGGV1MCsw/s1600/wallpaper2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5enV7AWI/AAAAAAAAAIs/XbvGGV1MCsw/s320/wallpaper2.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5xm7o9NI/AAAAAAAAAI0/rjgOh1OS5tQ/s1600/copyright-law.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Furthermore, to ensure a good level of credibility, the strategy uses the legal aspect of the present as set forth in the &lt;b&gt;Copyright Law of the European Union&lt;/b&gt;, and displays information from the headquarters of the agency who understands this type of conflict, depending on country is the victim.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5xm7o9NI/AAAAAAAAAI0/rjgOh1OS5tQ/s1600/copyright-law.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5xm7o9NI/AAAAAAAAAI0/rjgOh1OS5tQ/s320/copyright-law.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O6A0ZYbJI/AAAAAAAAAI8/dl5l66idQFE/s1600/get.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;For geo-location information, the malware establishes a connection from IP address &lt;b&gt;91.209.238.2&lt;/b&gt; found in &lt;i&gt;Moldova, Republic Of Eugenia E. Groza&lt;/i&gt; reporting IP address, and then do a whois to establish the country of origin of the victim.&lt;/div&gt;&lt;br /&gt;&amp;gt; 91.209.238.2/m5tools/ip.php&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; 91.209.238.2/m5tools/whois.php&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O6A0ZYbJI/AAAAAAAAAI8/dl5l66idQFE/s1600/get.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O6A0ZYbJI/AAAAAAAAAI8/dl5l66idQFE/s320/get.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Press the Ctrl + Alt + Del to bring up task manager.&lt;br /&gt;End process "&lt;b&gt;iqmanager.exe&lt;/b&gt;"&lt;br /&gt;Delete the folder &lt;b&gt;IQmanager&lt;/b&gt; that is located in C:\Documents and Settings\Administrator\Application Data&lt;br /&gt;Delete the Desktop icon&lt;br /&gt;&lt;br /&gt;Enter the code below: &lt;b&gt;RFHM2-TPX47-YD6RT-H4KDM&lt;/b&gt; &lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html" style="color: orange;"&gt;New variant of ransomware through porn sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="color: orange;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: orange;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: orange;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html" style="color: orange;"&gt;Desktop Hijack by Internet Security 2010. Your System Is Infected!&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html" style="color: orange;"&gt;LockScreen. Your computer is infected by Spyware!!!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6835788720123613275?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6835788720123613275/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6835788720123613275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6835788720123613275'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/04/copyright-violation-copyrighted-content.html' title='Copyright violation: copyrighted content detected'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9O5NAWHPtI/AAAAAAAAAIk/VuofERnZFAk/s72-c/copyright-violation.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-724512020089394714</id><published>2010-04-19T16:03:00.000-07:00</published><updated>2010-04-19T16:05:08.285-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><title type='text'>New variant of ransomware through porn sites</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfdIWPbiI/AAAAAAAAAIU/dvPaCh2FzZw/s1600/alert1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The targets of this &lt;b&gt;ransomware&lt;/b&gt; are the visitors to pornographic sites. In this case it's a type ransom "&lt;b&gt;Blocker&lt;/b&gt;" that when activated displays a little message, and in the lower right corner of the screen, an image with pornographic content.&lt;/div&gt;&lt;br /&gt;Here is an example:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfdIWPbiI/AAAAAAAAAIU/dvPaCh2FzZw/s1600/alert1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfdIWPbiI/AAAAAAAAAIU/dvPaCh2FzZw/s320/alert1.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfk2QLi9I/AAAAAAAAAIc/9cnYmDc3lNc/s1600/ransom.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfk2QLi9I/AAAAAAAAAIc/9cnYmDc3lNc/s320/ransom.png" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Calls on sending an SMS message like the number 3862816 with the text&amp;nbsp; 8353 in order to unlock the opening of this picture, besides eliminating the automatic opening of &lt;i&gt;pornhub.com&lt;/i&gt; porn site (146.82.200.125).&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;The malware, which MD5 is db836ddad526869bc750b62fbe36e936 has a low level of detection: &lt;a href="http://www.virustotal.com/analisis/b57b1f203d931c81c3d936651b78b9118ab45bc9396f51c3adc74715cde4fd7b-1271237096" style="color: orange;"&gt;6/40 (15.00%)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Delete the following processes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;plugin.exe&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;watcher.exe&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Delete the folder hosted on Media &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;C:\Documents and Settings\All Users\Media&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Delete the following registry key:&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Module &amp;gt; c:\documents and settings\all users\media\plugin.exe&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;Related information&lt;/b&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html" style="font-family: inherit;"&gt;Dangerous trojans, keyloggers and Spyware detected in you computer!!!&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange; font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;/div&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html"&gt;LockScreen. Your computer is infected  by Spyware!!!&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-724512020089394714?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/724512020089394714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/724512020089394714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/724512020089394714'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/04/new-variant-of-ransomware-through-porn.html' title='New variant of ransomware through porn sites'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S8zfdIWPbiI/AAAAAAAAAIU/dvPaCh2FzZw/s72-c/alert1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-7526155492827539367</id><published>2010-03-13T06:12:00.000-08:00</published><updated>2010-08-21T12:23:49.802-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><title type='text'>Dangerous trojans, keyloggers and Spyware detected in you computer!!!</title><content type='html'>&lt;div style="text-align: justify;"&gt;This is a new variant of &lt;b&gt;ransomware&lt;/b&gt; that is In-the-Wild with, so far, a poor detection rate, the report from VirusTotal. &lt;a href="http://www.virustotal.com/analisis/954a197c3e9fb9374ddd322f5ea5630552c40021c0f6599faa274f16713e6012-1268478069" style="color: orange;"&gt;Only 9 of 42 detected by antivirus engines&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5uYZHrVnfI/AAAAAAAAAH8/cBBZ8uj1eUg/s1600-h/ls.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5uYZHrVnfI/AAAAAAAAAH8/cBBZ8uj1eUg/s320/ls.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It's a technique used by some &lt;a href="http://malwareint.blogspot.com/2010/01/recent-tour-of-scareware-xx.html" style="color: orange;"&gt;scareware&lt;/a&gt; aggressive to try to "compel" the victims to "buy" the alleged antivirus solution is, in fact, the &lt;b&gt;scareware&lt;/b&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;In this case, the malware is hidden under a file called &lt;b&gt;avlck.exe&lt;/b&gt; &lt;span style="font-size: x-small;"&gt;(md5:&lt;b&gt; 04cb597a4ffddfbae9a76cde53833ab7&lt;/b&gt;)&lt;/span&gt;. When run blocking access to the system screen showing the image above position which is expressed in an alleged problem of infection.&lt;/div&gt;&lt;br /&gt;In that instance the malware connects to the site&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5ubEUo0xeI/AAAAAAAAAIE/BrQyz5t1FEw/s1600-h/fraud.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5ubEUo0xeI/AAAAAAAAAIE/BrQyz5t1FEw/s320/fraud.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Make a copy of itself into the Windows System folder under the name &lt;b&gt;myserv.exe&lt;/b&gt;, and a reference in the registry Run key.&lt;/div&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;KeyMy c:\windows\myserv.exe&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-size: x-large;"&gt;&lt;b&gt;Countermeasures&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Restart in &lt;b&gt;Safe Mode&lt;/b&gt; and delete the file &lt;b&gt;myserv.exe&lt;/b&gt; found in the Windows folder.&lt;br /&gt;Delete the reference &lt;b&gt;KeyMy&lt;/b&gt; (&lt;b&gt;c:\windows\myserv.exe&lt;/b&gt;) located in &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Unlock the system to any of the following keys:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;PozisyonAyarla &lt;/b&gt;&lt;br /&gt;&lt;b&gt;HerZamanUstte&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related information &lt;/b&gt;&lt;br /&gt;&lt;div style="color: orange;"&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html" style="color: #ff9900;"&gt;Another very active SMS Ransomware&lt;/a&gt;&lt;/div&gt;&lt;a href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html" style="color: #ff9900;"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html" style="color: #ff9900;"&gt;LockScreen. Your computer is infected by Spyware!!!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-7526155492827539367?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/7526155492827539367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7526155492827539367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7526155492827539367'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/dangerous-trojans-keyloggers-and.html' title='Dangerous trojans, keyloggers and Spyware detected in you computer!!!'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5uYZHrVnfI/AAAAAAAAAH8/cBBZ8uj1eUg/s72-c/ls.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2772053487958299670</id><published>2010-03-07T17:48:00.000-08:00</published><updated>2010-03-07T17:48:17.101-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='papers'/><title type='text'>myLoader. Base C&amp;C to manage Oficla/Sasfis Botnet</title><content type='html'>&lt;h1&gt;&lt;/h1&gt;&lt;div id="mainabout"&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.malwareint.com/images/ml-t.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5422537882371524274" src="http://www.malwareint.com/images/ml-t.png" style="cursor: pointer; float: left; height: 200px; margin: 0pt 10px 10px 0pt; width: 146px;" /&gt;&lt;/a&gt; myLoader a particular purpose Framework developed to manage the activities of a botnet. The data reflected in this report were collected based on the study of the criminal activities of a botnet containing a quantity of more than 210,000 zombies zombies.&lt;br /&gt;&lt;br /&gt;We describe the potential threat of this crime through the breakdown of the modules comprising the package that allows the management of the botnet ophicleide / Sasfis. Also presents some information that helps explain his behavior both in propagation strategy as in the processes of infection and prevention to help counteract their actions.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/myloader-oficla-analysis-es.pdf" style="color: #3333ff;"&gt;&lt;b&gt;Spanish&lt;/b&gt;&lt;/a&gt; |  &lt;a href="http://www.malwareint.com/docs/myloader-oficla-analysis-en.pdf" style="color: #3333ff;"&gt;&lt;b&gt;English&lt;/b&gt;&lt;/a&gt; | Author: Jorge Mieres | &lt;b&gt;Malware &lt;span class="blue"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; | 2010, March &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2772053487958299670?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2772053487958299670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/myloader-base-c-to-manage-oficlasasfis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2772053487958299670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2772053487958299670'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/myloader-base-c-to-manage-oficlasasfis.html' title='myLoader. Base C&amp;C to manage Oficla/Sasfis Botnet'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-457851379116032744</id><published>2010-03-05T05:00:00.000-08:00</published><updated>2010-03-05T06:30:51.960-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><title type='text'>Another very active SMS Ransomware</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Ransomware&lt;/span&gt; activities originating with Russia don't stop. Constantly looking for committing fraudulent business feeding the information located in the system.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;In this case, it's another ransomware that is In-the-Wild, and &lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/becc479442c65d7a6da6fdd8e27e105f47e0a6ba979a2338daa1337d66dbdcbe-1249166235"&gt;its detection rate is very low&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S5Cgj6lv0sI/AAAAAAAACPs/nRBV45VvXQg/s1600-h/lock_ransom.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 263px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S5Cgj6lv0sI/AAAAAAAACPs/nRBV45VvXQg/s400/lock_ransom.png" alt="" id="BLOGGER_PHOTO_ID_5445028488374375106" border="0" /&gt;&lt;/a&gt;When the malicious binary is executed, it causes an alleged error in IE.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5Cgqg-R2AI/AAAAAAAACP0/q1zuJQV-Jrk/s1600-h/lockscreen_ie-error.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 263px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5Cgqg-R2AI/AAAAAAAACP0/q1zuJQV-Jrk/s400/lockscreen_ie-error.png" alt="" id="BLOGGER_PHOTO_ID_5445028601757030402" border="0" /&gt;&lt;/a&gt;Just create a plain text file called &lt;span style="font-weight: bold;"&gt;xFoLOOOSErs.txt&lt;/span&gt; with the following information:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;installed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;19793214&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;And creates a registry key.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5CgxEf7GXI/AAAAAAAACP8/E6CidrLq39U/s1600-h/reg.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 14px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5CgxEf7GXI/AAAAAAAACP8/E6CidrLq39U/s400/reg.png" alt="" id="BLOGGER_PHOTO_ID_5445028714372602226" border="0" /&gt;&lt;/a&gt;The number stored in this file corresponds to the telephone number the user must send an SMS to unlock the system. However, this is not the only number that uses the cyber criminal, and that also can display the following:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1971482&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;19777877&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;197852&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;197971412&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Furthermore, the number of activation may vary between:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;5370&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;5373&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;7250&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Technical data:&lt;/span&gt;&lt;br /&gt;MD5: 0cc435c5bfe3444ce7151f8f2a319728&lt;br /&gt;SHA1: 9c00c70b220da9b59fc9be55d37d7a1f94abb2e0&lt;br /&gt;File size: 71168 bytes&lt;br /&gt;Packer: -&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;Countermeasures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;For any telephone numbers used by this variant of ransomware and above can use any of the following codes:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;0000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1973143&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Maintain updated antivirus program.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: left; color: rgb(255, 153, 0);"&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html"&gt;SMS Ransomware for Windows In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html"&gt;LockScreen. Your computer is infected by Spyware!!!&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-457851379116032744?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/457851379116032744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/457851379116032744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/457851379116032744'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/another-very-active-sms-ransomware.html' title='Another very active SMS Ransomware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S5Cgj6lv0sI/AAAAAAAACPs/nRBV45VvXQg/s72-c/lock_ransom.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2118374984033021801</id><published>2010-03-04T20:55:00.000-08:00</published><updated>2010-03-13T16:38:38.150-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><title type='text'>SMS Ransomware for Windows In-the-Wild</title><content type='html'>&lt;div style="text-align: justify;"&gt;Within the criminal business of the malicious code, a variant of well-known are the strategies implemented by &lt;span style="font-weight: bold;"&gt;ransomware&lt;/span&gt; malware type, where the main objective is financial gain in exchange for the return of something maliciously "&lt;span style="font-weight: bold;"&gt;hijacked&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;In this case, it's the operating system crash by a malware Russian origin. According to the nomenclature of antivirus companies, the same is detected under names alluding to &lt;span style="font-weight: bold;"&gt;Blocker&lt;/span&gt; (Comodo/Fortinet/Kaspersky), &lt;span style="font-weight: bold;"&gt;LooksLike&lt;/span&gt; (McAfee), &lt;span style="font-weight: bold;"&gt;LockScreen&lt;/span&gt; (ESET), &lt;span style="font-weight: bold;"&gt;Fraud&lt;/span&gt; (Avast), &lt;span style="font-weight: bold;"&gt;Winlock&lt;/span&gt; (DrWeb), &lt;span style="font-weight: bold;"&gt;Dunik! Rts&lt;/span&gt; ( Microsoft).&lt;br /&gt;&lt;br /&gt;Malware pretends to be the executable to install Flash Player using a file called &lt;span style="font-weight: bold;"&gt;install_flash_player.exe&lt;/span&gt; &lt;span style="font-size:85%;"&gt;(&lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/79943dae369d504a80ffb3b0515fd8049646abdd2aa182bf6ed42f969f0cf04c-1267560455"&gt;ff27289c8a5ac530ce876bc08fe45f1e&lt;/a&gt;)&lt;/span&gt;.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/S5CQNsMOHGI/AAAAAAAACPk/GJumwDyXe2U/s1600-h/install.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 317px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/S5CQNsMOHGI/AAAAAAAACPk/GJumwDyXe2U/s400/install.png" alt="" id="BLOGGER_PHOTO_ID_5445010514366045282" border="0" /&gt;&lt;/a&gt;However, to be executed, the operating system crashes through a window, which is expressed in the Russian language (a feature which indicates its orientation toward the Russian audience) the order to send a text message &lt;span style="font-weight: bold;"&gt;SMS&lt;/span&gt; to a particular type phone number to get the unlock key.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5CPUid5VUI/AAAAAAAACPc/0dRQy6yVIlk/s1600-h/05-03-2010+01-47-04+a.m..png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 237px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5CPUid5VUI/AAAAAAAACPc/0dRQy6yVIlk/s400/05-03-2010+01-47-04+a.m..png" alt="" id="BLOGGER_PHOTO_ID_5445009532503283010" border="0" /&gt;&lt;/a&gt;Generated in the folder &lt;span style="font-style: italic;"&gt;%temp%&lt;/span&gt; the files asd [x].cbt (&lt;span style="font-size:85%;"&gt;D6110298A4E241BE6E7031ADA220BACC&lt;/span&gt;) and asd[x].tmp (this is a MZ file) (&lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/a9b0a6747a80ddc2c66300197dc53d1475f702bb083e0f0cee7a2968b8b7c67d-1264452837"&gt;&lt;span style="font-size:85%;"&gt;5E9C2819DA8463278F0CFA3C1CCAFF70&lt;/span&gt;&lt;/a&gt;), where [x] is a random number, found under the nomenclature &lt;span style="font-weight: bold;"&gt;Ransom PogBlock&lt;/span&gt; by some AV companies. The latter is the binary that controls the pop-up blocking system.&lt;br /&gt;&lt;br /&gt;The ransomware disables the &lt;span style="font-style: italic;"&gt;Task Manager&lt;/span&gt; and blocks the ability to access the system in &lt;span style="font-style: italic;"&gt;Safe Mode&lt;/span&gt; by generating a reboot loop through a&lt;span style="font-weight: bold;"&gt; BSoD&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S5CPP6bDQbI/AAAAAAAACPU/F3afsTu2KRY/s1600-h/bsod.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 263px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S5CPP6bDQbI/AAAAAAAACPU/F3afsTu2KRY/s400/bsod.png" alt="" id="BLOGGER_PHOTO_ID_5445009453034455474" border="0" /&gt;&lt;/a&gt;This activity is under the framework of the business of criminal malware itself, which the malware author attempts through the cost benefit that requires the sending of SMS. A more within the criminal world of crimeware that even if it's addressed to the Russian public, constitutes a serious threat to any system.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;Countermeasures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Restart in Safe Mode.&lt;br /&gt;Delete the file asd[x].tmp alocated in &lt;span style="font-style: italic;"&gt;%temp%&lt;/span&gt;.&lt;br /&gt;Delete the following registry key:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;c:\documents and settings\administrador\configuración local\temp\asd1.tmp&lt;/span&gt;&lt;br /&gt;Maintain updated antivirus program.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The easiest part&lt;/span&gt;. Unblock with any of the following keys:&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;code:&lt;span style="font-weight: bold;"&gt;592100041&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;2002972524&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592131650&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;3807350716&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592108426&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;2111921530&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592128602&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;838761711&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592122374&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;4272582034&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592100773&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;3071200006&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592109181&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;2803729885&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592109325&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;1494973728&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592129826&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;3062337563&lt;/span&gt;&lt;br /&gt;code:&lt;span style="font-weight: bold;"&gt;592105732&lt;/span&gt; unlock:&lt;span style="font-weight: bold;"&gt;2478558886&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Note&lt;/span&gt;: Should appear on your display a different number for those exposed, send an email to with the number disastersteam[at]malwareint[dot]com to receive the unlock key.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html"&gt;LockScreen. Your computer is infected by Spyware!!!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2118374984033021801?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2118374984033021801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2118374984033021801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2118374984033021801'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/03/sms-ransomware-for-windows-in-wild.html' title='SMS Ransomware for Windows In-the-Wild'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/S5CQNsMOHGI/AAAAAAAACPk/GJumwDyXe2U/s72-c/install.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-360991428517383213</id><published>2010-02-23T17:31:00.000-08:00</published><updated>2010-03-01T17:44:25.597-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='papers'/><title type='text'>SpyEye Bot (Part two). Conversations with the creator of crimeware</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S37ftXI_oHI/AAAAAAAAAGI/jbfn6Wm2etw/s1600-h/spyeye_2.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img style="width: 144px; height: 183px;" src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S37ftXI_oHI/AAAAAAAAAGI/jbfn6Wm2etw/s320/spyeye_2.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;In recent weeks, SpyEye (a new financial trojan) has been the talk of many for the positive acceptance was so in the underground scene due to its balance about cost/benefit, and the great impact that achievement to whiten the features in its latest version that allows systems to eliminate the activities of your competition: ZeuS.&lt;br /&gt;&lt;br /&gt;Our previous report, “SpyEye. Analysis of a new crimeware alternative scenario,” addressed known technical issues involving the activities of this threat.&lt;br /&gt;&lt;br /&gt;In this second part we present the exclusive interview by Ben Koehl, Crimeware Researcher of Malware Intelligence. Through interviews with the creator of crimeware, we reveal information that shows some of the thought process and brains behind the creator of SpyEye. We also see the source code for the Zeus Killer addition.&lt;br /&gt;&lt;br /&gt;The way that Gribodemon thinks is not unique anymore in the cybercrime world. We are seeing individuals and groups becoming more specialized in the services they provide and are no longer spreading themselves thin. There are many industries within the cybercrime world. From coding to infrastructure support to public relations.&lt;br /&gt;&lt;br /&gt;There was a large language barrier between me and the author so I had to keep the questions short and basic so his translator program could handle them (Lingvo.)  We broke up the conversation in pieces to make it flow better to the reader.&lt;/div&gt;&lt;br /&gt;This document can be downloaded from:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/spyeye-analysis-ii-en.pdf" style="color: rgb(255, 153, 0);"&gt;English version&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.malwareint.com/docs/spyeye-analysis-ii-es.pdf"&gt;Spanish version&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html" style="color: rgb(255, 153, 0);"&gt;SpyEye Bot. New bot on the market&lt;/a&gt;&lt;br /&gt;&lt;a href="http://mipistus.blogspot.com/2010/01/el-crimeware-durante-el-2009.html" style="color: rgb(255, 153, 0);"&gt;Compendio Anual de Información. El crimeware durante el 2009&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html" style="color: rgb(51, 51, 255);"&gt;&lt;br /&gt;&lt;/a&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-360991428517383213?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/360991428517383213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/02/spyeye-bot-part-two-conversations-with.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/360991428517383213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/360991428517383213'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/02/spyeye-bot-part-two-conversations-with.html' title='SpyEye Bot (Part two). Conversations with the creator of crimeware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S37ftXI_oHI/AAAAAAAAAGI/jbfn6Wm2etw/s72-c/spyeye_2.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-8825099340937769273</id><published>2010-02-10T14:13:00.000-08:00</published><updated>2010-03-01T17:45:09.704-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='papers'/><title type='text'>SpyEye Bot. Analysis of a new alternative scenario crimeware</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s1600-h/mi-paper-se-en.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 139px; height: 200px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s200/mi-paper-se-en.png" alt="" id="BLOGGER_PHOTO_ID_5436740634761332994" border="0" /&gt;&lt;/a&gt;Earlier this year saw the light in the underground black market that moves the axes of &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;, a new application designed to provide feedback for criminal and fraudulent business.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;This application, called &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html"&gt;SpyEye&lt;/a&gt;, is aimed at facilitating the recruitment of zombies and managing your network (&lt;span style="font-weight: bold;"&gt;C&amp;amp;C&lt;/span&gt; - &lt;span style="font-weight: bold;"&gt;Command and Control&lt;/span&gt;) through management panel via the web, from which it is possible to process the information obtained (&lt;a style="color: rgb(255, 153, 0);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html"&gt;intelligence&lt;/a&gt;) and stored in statistics, a common activity of criminal packages today.&lt;br /&gt;&lt;br /&gt;Depending on their characteristics, very similar to those proposed by his counterpart &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2010/01/zeus-and-theft-of-sensitive-information.html"&gt;ZeuS&lt;/a&gt;, &lt;span style="font-weight: bold;"&gt;SpyEye&lt;/span&gt; is presented as a potential successor to this within the scenario crimeware. Furthermore, it is evident that the criminal activities now represent a large business where cyber criminals and would-be cyber criminals abuse their "kindness".&lt;br /&gt;&lt;br /&gt;This document describes the activities of &lt;span style="font-weight: bold;"&gt;SpyEye&lt;/span&gt; from the stage of infection giving relevant information about their purpose.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;The full document can be downloaded from:&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.malwareint.com/docs/spyeye-analysis-es.pdf"&gt;Spanish version&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.malwareint.com/docs/spyeye-analysis-en.pdf"&gt;English version&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://mipistus.blogspot.com/2010/01/el-crimeware-durante-el-2009.html"&gt;Compendio Anual de Información. El crimeware durante el 2009&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html"&gt;SpyEye Bot. New bot on the market&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-8825099340937769273?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/8825099340937769273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/02/spyeye-bot-analysis-of-new-alternative.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8825099340937769273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/8825099340937769273'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/02/spyeye-bot-analysis-of-new-alternative.html' title='SpyEye Bot. Analysis of a new alternative scenario crimeware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s72-c/mi-paper-se-en.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6059267701597301631</id><published>2010-01-05T09:03:00.000-08:00</published><updated>2010-03-01T17:45:35.228-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='papers'/><title type='text'>Crimeware in 2009</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S0N91jQB45I/AAAAAAAACHc/g36mqQeX3BI/s1600-h/malwareint-anual-t.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 146px; height: 200px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S0N91jQB45I/AAAAAAAACHc/g36mqQeX3BI/s200/malwareint-anual-t.png" alt="" id="BLOGGER_PHOTO_ID_5423316735233221522" border="0" /&gt;&lt;/a&gt;"&lt;span style="font-weight: bold;"&gt;Crimeware in 2009&lt;/span&gt;" presented in one document all that was channeled through this blog during the year in question on &lt;span style="font-weight: bold;"&gt;crimeware &lt;/span&gt;and associated hazards.&lt;br /&gt;&lt;br /&gt;There are a total of 262 pages and is divided by the most relevant topics that describe the criminal activities that were a source of news on this blog. Has two indices for getting the news in a simple (content) and another on the images (image index).&lt;br /&gt;&lt;br /&gt;Then let some of the themes they found in the document in question:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Current business outlook caused by crimeware&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets general purpose&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets particular purpose&lt;/li&gt;&lt;li&gt;Services associated with crimeware&lt;/li&gt;&lt;li&gt;Intelligence in the fight against crimeware&lt;/li&gt;&lt;li&gt;Campaigns of spread and infection&lt;/li&gt;&lt;li&gt;Other Exploits packs that were investigated&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Short information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.malwareint.com/"&gt;Malware Intelligence&lt;/a&gt;&lt;br /&gt;Annual compendium of information. Crimeware in 2009&lt;br /&gt;262 pages&lt;br /&gt;Spanish language&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.malwareint.com/docs/MalwareInt-anual-2009.pdf"&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;Download&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6059267701597301631?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6059267701597301631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2010/01/crimeware-in-2009.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6059267701597301631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6059267701597301631'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2010/01/crimeware-in-2009.html' title='Crimeware in 2009'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S0N91jQB45I/AAAAAAAACHc/g36mqQeX3BI/s72-c/malwareint-anual-t.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-6174550596591646577</id><published>2009-12-26T12:22:00.000-08:00</published><updated>2010-03-01T17:46:21.341-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><title type='text'>Desktop Hijack by Internet Security 2010. Your System Is Infected!</title><content type='html'>&lt;div style="text-align: justify;"&gt;The &lt;span style="font-weight: bold;"&gt;Desktop Hijack&lt;/span&gt; is to "hijack" the desktop background, changing the image and blocking its configuration defined in a way that this can not be restored. This is a clear indication that the system was the victim of a malicious code, a kind of &lt;span style="font-weight: bold;"&gt;rogue&lt;/span&gt;, also known as &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2009/12/recent-tour-of-scareware-xix.html"&gt;scareware&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Internet Security 2010&lt;/span&gt; is a rogue who performs this activity. The same is distributed through a crimeware called &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2009/12/siberia-exploit-pack-another-package-of.html"&gt;Siberia Exploit Pack&lt;/a&gt;. Below is a screenshot of the Desktop Hijack.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZw2RLOW0I/AAAAAAAACEw/85-QZeKiC4k/s1600-h/mipistus-destop-hijack-IAV2010.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 252px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZw2RLOW0I/AAAAAAAACEw/85-QZeKiC4k/s400/mipistus-destop-hijack-IAV2010.png" alt="" id="BLOGGER_PHOTO_ID_5419643279212698434" border="0" /&gt;&lt;/a&gt;When this malware infects your system, then block the Desktop background settings, installs in the &lt;span style="font-style: italic;"&gt;Program Files&lt;/span&gt; folder. &lt;span style="font-weight: bold;"&gt;This threat is aimed at Windows platforms infection in English&lt;/span&gt;, so that those who have Spanish versions aren't affected. We then see a screenshot of the interface of the rogue.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZw9jeFGEI/AAAAAAAACE4/Qj7kQxM9oIc/s1600-h/mipistus-interfaz.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 295px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZw9jeFGEI/AAAAAAAACE4/Qj7kQxM9oIc/s400/mipistus-interfaz.png" alt="" id="BLOGGER_PHOTO_ID_5419643404382705730" border="0" /&gt;&lt;/a&gt;Each particular seconds, deploy dissuasive actions designed to generate "fear" in the user through warnings about malicious activity generated by alleged infections. Some of the warnings are:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SzZxaFJusqI/AAAAAAAACFA/xE5oXURfjHI/s1600-h/mipistus-pop-ups.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 205px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SzZxaFJusqI/AAAAAAAACFA/xE5oXURfjHI/s400/mipistus-pop-ups.png" alt="" id="BLOGGER_PHOTO_ID_5419643894460494498" border="0" /&gt;&lt;/a&gt;In order for the user, looking for a solution to the alleged problems of infection, finish buying the full version of the antivirus program. To which, in this instance, you must access via a web form from which you request the "product", even, in some cases you may find advice&lt;span style="color: rgb(255, 153, 0);"&gt; &lt;/span&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2009/12/anti-virus-live-2010-talking-with-enemy.html"&gt;in real time&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZxlwhkbhI/AAAAAAAACFI/UtCHXAXyEYo/s1600-h/mipistus-iav2010-purchase.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 322px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZxlwhkbhI/AAAAAAAACFI/UtCHXAXyEYo/s400/mipistus-iav2010-purchase.png" alt="" id="BLOGGER_PHOTO_ID_5419644095081770514" border="0" /&gt;&lt;/a&gt;This &lt;span style="font-style: italic;"&gt;modus operandi&lt;/span&gt; is common and is a rogue employer, including "purchase form" that in many cases until they are supported by https. In this case, &lt;span style="font-weight: bold;"&gt;Internet Security 2010&lt;/span&gt;, is marketed at a cost of nearly &lt;span style="font-weight: bold;"&gt;USD 50&lt;/span&gt;, so if you believe that its spread is related to a &lt;span style="font-weight: bold;"&gt;botnet&lt;/span&gt;, is easy to deduce the amount of money that criminals get through this type of activities.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;Countermeasures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Terminate the processes called &lt;span style="font-weight: bold;"&gt;winupdate86.exe&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;IS2010.exe&lt;/span&gt; (eventually you can find the process &lt;span style="font-weight: bold;"&gt;winlogon86.exe&lt;/span&gt;).&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;NOTE&lt;/span&gt;: The malware can deshactiva conventionally access to cmd, registry and the Task Manager, therefore, to complete the process easily recommend using &lt;a style="color: rgb(255, 153, 0);" href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx"&gt;Process Explorer&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SzZxwfvxAtI/AAAAAAAACFQ/h8EMErQjxRE/s1600-h/mipistus-warning.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 96px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SzZxwfvxAtI/AAAAAAAACFQ/h8EMErQjxRE/s400/mipistus-warning.png" alt="" id="BLOGGER_PHOTO_ID_5419644279556473554" border="0" /&gt;&lt;/a&gt;Then, access the system registry and delete the following keys:&lt;br /&gt;In &lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt; delete the key &lt;span style="font-weight: bold;"&gt;Internet Security 2010&lt;/span&gt;.&lt;br /&gt;Under &lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt; delete the key &lt;span style="font-weight: bold;"&gt;winupdate86.exe&lt;/span&gt;.&lt;br /&gt;Under &lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Userinit&lt;/span&gt;&lt;/span&gt; change the call reference that points to &lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;C:\WINDOWS\system32\winlogon86.exe&lt;/span&gt;&lt;/span&gt; with &lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;C:\WINDOWS\system32\userinit.exe&lt;/span&gt;&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Unregister the dll call &lt;span style="font-weight: bold;"&gt;winhelper86.dll&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;NOTE&lt;/span&gt;: To perform this action you must access the &lt;span style="font-style: italic;"&gt;Start/Run/cmd&lt;/span&gt; and type &lt;span style="font-weight: bold;"&gt;regsvr32 /u [dll name]&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SzZx5aTrB3I/AAAAAAAACFY/3-W2RdtfsEQ/s1600-h/mipistus-cmd..png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 141px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SzZx5aTrB3I/AAAAAAAACFY/3-W2RdtfsEQ/s400/mipistus-cmd..png" alt="" id="BLOGGER_PHOTO_ID_5419644432715286386" border="0" /&gt;&lt;/a&gt; Delete the folder &lt;span style="font-weight: bold;"&gt;InternetSecurity2010 &lt;/span&gt;located at &lt;span style="font-weight: bold;"&gt;C:\Program Files&lt;/span&gt;, and files &lt;span style="font-weight: bold;"&gt;41.exe&lt;/span&gt; (this number may vary found files with numeric names such as&lt;span style="font-style: italic;"&gt; 5705.exe&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;28145.exe&lt;/span&gt;, etc.), &lt;span style="font-weight: bold;"&gt;winhelper86.dll&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;winlogon86.exe&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;winupdate86.exe&lt;/span&gt; found in &lt;span style="font-weight: bold;"&gt;C:\WINDOWS\system32\.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Remove also the direct link called&lt;span style="font-style: italic;"&gt; Internet Security 2010&lt;/span&gt; which is on the Desktop and reboot the machine.&lt;br /&gt;&lt;br /&gt;Install and run an updated antivirus&lt;br /&gt;&lt;br /&gt;Malware Disasters Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-6174550596591646577?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/6174550596591646577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6174550596591646577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/6174550596591646577'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/desktop-hijack-by-internet-security.html' title='Desktop Hijack by Internet Security 2010. Your System Is Infected!'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzZw2RLOW0I/AAAAAAAACEw/85-QZeKiC4k/s72-c/mipistus-destop-hijack-IAV2010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-7114116219134802908</id><published>2009-12-14T20:08:00.000-08:00</published><updated>2010-03-04T18:09:15.652-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>LockScreen. Your computer is infected by Spyware!!!</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;LockScreen&lt;/span&gt; is a &lt;span style="font-weight: bold;"&gt;trojan&lt;/span&gt; designed to block access to the operating system as a primary resource using the fear factor.&lt;br /&gt;&lt;br /&gt;First, when activated displays a warning about an alleged infection caused by &lt;span style="font-weight: bold;"&gt;spyware&lt;/span&gt;, inciting to buy an antispyware which is really other malicious code. On the other hand, states that "if not eliminate spyware from the system in three hours, will be formatted".&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SycL8wuOsxI/AAAAAAAACDA/v0g2biO9SmI/s1600-h/mipistus-you-comp.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 263px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SycL8wuOsxI/AAAAAAAACDA/v0g2biO9SmI/s400/mipistus-you-comp.png" alt="" id="BLOGGER_PHOTO_ID_5415310215435170578" border="0" /&gt;&lt;/a&gt;Thus, the user victim of this malicious code will be forced to take extreme measures to try to access the operating system, or accept the purchase of a false solution to get the unlock key.&lt;br /&gt;&lt;br /&gt;This activity is typical of the concept &lt;span style="font-weight: bold;"&gt;ransomware&lt;/span&gt;, which produces the "kidnapping" of the operating system or part thereof, but through more complex processes which usually involves some encryption algorithm and the "payment" (usually money) to obtain the unlock key.&lt;br /&gt;&lt;br /&gt;Although malware isn't a complex, currently has a low detection rate, being detected only by 11 antivirus companies a total of 41, as shown in the &lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/0336fb33a2aef6959113cc6a6a556e66fce08c791628b901d7e506f60769d744-1260849774"&gt;report of VirusTotal&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Technical Data&lt;/span&gt;&lt;br /&gt;MD5: f3a7d1054e79dda8e8a16901d95770e1&lt;br /&gt;SHA1: c1887445b1fd5d89f61e638231d554c5bcff49ab&lt;br /&gt;File size: 32768 bytes&lt;br /&gt;Packer: -&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;Countermeasure&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Restart the computer in Safe Mode Errors (by pressing the F8 key during startup) and delete the file "&lt;span style="font-style: italic;"&gt;benimserverim.exe&lt;/span&gt;" which is hosted in the Windows folder.&lt;br /&gt;&lt;br /&gt;Then clean the system registry by removing the key "&lt;span style="font-style: italic;"&gt;benimAnahtar&lt;/span&gt;" from &lt;span style="font-family:courier new;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SycMB3h2szI/AAAAAAAACDI/TAAiKFkJJCE/s1600-h/registro-lock.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 78px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SycMB3h2szI/AAAAAAAACDI/TAAiKFkJJCE/s400/registro-lock.png" alt="" id="BLOGGER_PHOTO_ID_5415310303161660210" border="0" /&gt;&lt;/a&gt;In case you can not restart the computer in Safe Mode Errors, another alternative is to restart the computer and for the moment, after the inception of the desktop is displayed, quickly press the Ctrl + Alt + Del to access the Task Manager and end the process called "&lt;span style="font-style: italic;"&gt;Project1&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;Then delete the file "&lt;span style="font-style: italic;"&gt;benimserverim.exe&lt;/span&gt;" hosted in the WINDOWS folder and the registry key "&lt;span style="font-style: italic;"&gt;benimAnahtar&lt;/span&gt;" found at &lt;span style="font-family:courier new;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Or... the password required to unlock the system is &lt;span style="font-weight: bold;"&gt;DosyaYolu&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Malware Disasters Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-7114116219134802908?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/7114116219134802908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7114116219134802908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/7114116219134802908'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/lockscreen-your-computer-is-infected-by.html' title='LockScreen. Your computer is infected by Spyware!!!'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SycL8wuOsxI/AAAAAAAACDA/v0g2biO9SmI/s72-c/mipistus-you-comp.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-4323394184750233707</id><published>2009-12-13T16:08:00.000-08:00</published><updated>2010-03-01T17:51:05.826-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>Waledac/Storm. Past and present a threat</title><content type='html'>&lt;p style="text-align: justify;"&gt;At the beginning of 2007 jumped from the darkness to begin a malicious code to be a source of important news because of their particular strategies of deception and a major campaign at the global level of infection that still remain a subject of research by the community security.&lt;br /&gt;&lt;br /&gt;This is &lt;span style="font-weight: bold;"&gt;Storm&lt;/span&gt;, aka &lt;span style="font-weight: bold;"&gt;Nuwar&lt;/span&gt; or &lt;span style="font-weight: bold;"&gt;Zhelatin&lt;/span&gt; depending on the identity assigned by the antivirus companies, although it's known as "storm", perhaps alluding to the manner in which systems ravaged by which he &lt;a href="http://mipistus.blogspot.com/2009/06/elfiesta-reclutamiento-zombi-traves-de.html" style="color: rgb(255, 153, 0);"&gt;transformed into zombies&lt;/a&gt;, recruiting teams under the command of the &lt;span style="font-weight: bold;"&gt;botnet&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;At present, the threat posed Storm hasn't been to one side, but transferred to its twin brother, &lt;span style="font-weight: bold;"&gt;Waledac&lt;/span&gt;, which remains essentially the characteristic of trying to innovate in terms of apology necessary for the spread and recently has awakened after a period of hibernation.&lt;br /&gt;&lt;/p&gt;Some features of this threat are:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;The spread is through the unwanted e-mail (spam) &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Uses deception strategies (Social Engineering) different for each campaign to spread &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Through a link embedded in the body of a message routed to a site where malware is downloaded &lt;/i&gt;&lt;br /&gt;&lt;i&gt;The infected computers are part of a botnet &lt;/i&gt;&lt;br /&gt;&lt;i&gt;To complete the cycle of infection through the spread of spam &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Fast-Flux networks &lt;/i&gt;&lt;br /&gt;&lt;i&gt;They have polymorphic capabilities at the server level&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; During virtually the entire 2007, Storm (the first appearances as a strategy of deception used to display a video on a storm unleashed in Europe) used as a means of propagation/infection e-mail with questions and topics varied inciting to click on a link embedded in the message body, which in some cases direction of a page (some of them also tried to spread Storm exploit vulnerabilities using &lt;span style="font-style: italic;"&gt;iframe&lt;/span&gt; tags as resources) and others directed to the download of a binary in Storm both cases.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/SpsgYl-68II/AAAAAAAAACo/Hb0yIFUu-mI/s1600-h/Storm2007.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/SpsgYl-68II/AAAAAAAAACo/Hb0yIFUu-mI/s320/Storm2007.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Already for next year (2008), Storm joined the "surprise effect" linking the e-mail link provided to a web site that accompanied the excuse presented in the case of mail with an image alluding also to the theme that, the as in 2007, rotating with each major event (Valentine's Day, Independence of the USA, Christmas, etc). In addition, some variants spread through blogs.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/SpsgzGFtMiI/AAAAAAAAACw/uu9PugCKxoo/s1600-h/mi_storm-grap.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/SpsgzGFtMiI/AAAAAAAAACw/uu9PugCKxoo/s320/mi_storm-grap.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;After several months of inactivity in terms of the spread of the threat, in January of this year appears Waledac, a trojan that uses the same mechanisms used by Storm and many security professionals are beginning to see the similarity between them.&lt;br /&gt;&lt;br /&gt;After several investigations, says that Waledac is, one might say, the twin brother of Storm. Using the same methodologies of &lt;a href="http://mipistus.blogspot.com/2009/01/tecnicas-de-engano-que-no-pasan-de-moda.html" style="color: rgb(255, 153, 0);"&gt;Social Engineering&lt;/a&gt; with a broad portfolio of images and themes used as an excuse to capture users' attention. Passing through images rather the typical "love" for the month of Valentine Cases of alleged terrorist attacks, among others, to the recent course on a video on YouTube.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/SpshLcC1V8I/AAAAAAAAAC4/QWl9msvPby4/s1600-h/mi-waledac-grap.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/SpshLcC1V8I/AAAAAAAAAC4/QWl9msvPby4/s320/mi-waledac-grap.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;There are, among others, two very interesting features in both Waledac Storm: the use of &lt;a href="http://mipistus.blogspot.com/2009/01/entendiendo-las-redes-fast-flux.html" style="color: rgb(255, 153, 0);"&gt;Fast-Flux networks&lt;/a&gt; and &lt;a href="http://mipistus.blogspot.com/2009/02/creacion-online-de-malware-polimorfico.html" style="color: rgb(255, 153, 0);"&gt;polymorphic capabilities&lt;/a&gt; on the server.&lt;br /&gt;&lt;br /&gt;The first of these threats were allowed to spread across different IP addresses and using different domain names that constantly rotate between each other with the name resolution. This causes, through a certain time to live (TTL) pre-configured every x amount of jumps between nodes (infected computers) from the same domain, you download a different prototype of malware.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; This leads to the second feature, the polymorphism. In this way, each time the package (malware) is established TTL attempt to download a different version of the malicious code to be "changes" every certain amount of time (also predetermined by the attacker) establishing capacity polymorphic.&lt;br /&gt;&lt;br /&gt;The diagram below provides the direct relationship, over time, the threat was used as a strategy of deception.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/SpshmDOTL7I/AAAAAAAAADA/-MoUIKhhN2A/s1600-h/mi-storm-waledac-grap.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/SpshmDOTL7I/AAAAAAAAADA/-MoUIKhhN2A/s320/mi-storm-waledac-grap.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Each of the zombies that are part of the botnet created by Waledac, focus your intentions in sending spam. In this sense, a very interesting extract from a report that says Waledac has the ability to send about &lt;a href="http://blogs.eset-la.com/laboratorio/2009/07/07/cuanto-spam-envia-waledac/" style="color: rgb(255, 153, 0);"&gt;150,000 spam emails per day&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Perhaps, then you know that Storm/Waledac are running campaigns with high rates of spread of infection globally and overcrowded, it's clear that their creators are continuing their criminal operations for a financial issue, which is nothing new for malware today.&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;span style="font-size:100%;"&gt;via &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2009/06/symbiosis-malware-present-koobface.html"&gt;Pistus Malware Intelligence Blog&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;Malware Disasters Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-4323394184750233707?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/4323394184750233707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/waledacstorm-past-and-present-threat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/4323394184750233707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/4323394184750233707'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/waledacstorm-past-and-present-threat.html' title='Waledac/Storm. Past and present a threat'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/SpsgYl-68II/AAAAAAAAACo/Hb0yIFUu-mI/s72-c/Storm2007.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2534927153970902867</id><published>2009-12-13T16:01:00.000-08:00</published><updated>2010-03-01T17:50:30.163-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>Symbiosis malware present. Koobface</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;b&gt;Koobface&lt;/b&gt; is a worm designed to exploit the user profiles of popular social networks like MySpace and FaceBook in order to obtain sensitive and confidential information of their victims, although the latest versions limiting their goal FaceBook. In fact, the word Koobface is a transposition of the word Facebook.&lt;br /&gt;&lt;br /&gt;His early versions date back to late 2008 and since then continues In-the-Wild with an infection rate of concern. Thus, the same company released a series of &lt;a href="http://www.facebook.com/security" style="color: rgb(255, 153, 0);"&gt;preventive measures&lt;/a&gt;&lt;span style="color: rgb(255, 153, 0);"&gt; &lt;/span&gt;to minimize the potential risk of infection, which is constantly latent for users who use the social network.&lt;br /&gt;&lt;br /&gt;In principle, the usual means of dissemination used Koobface is via web through visual&lt;b&gt; Social Engineering&lt;/b&gt; and is the first facet of propagation.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sj6e71Uu06I/AAAAAAAABgg/VQ_YiCmmlAQ/s1600-h/koobface.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" style="font-family: arial;"&gt;&lt;img alt="" id="BLOGGER_PHOTO_ID_5349888158126232482" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sj6e71Uu06I/AAAAAAAABgg/VQ_YiCmmlAQ/s400/koobface.jpg" style="margin: 0px auto 10px; cursor: pointer; display: block; height: 274px; text-align: center; width: 400px;" border="0" /&gt;&lt;/a&gt;The second facet (infection) channeled their malicious actions in a very common at present, based on a combination of malware, creating a symbiosis where each component of ambient display instructions to seek a common objective and comprehensive.&lt;br /&gt;&lt;br /&gt;But let's see which are these components that form a part of the stage of infection of the variant &lt;a href="http://www.virustotal.com/analisis/be9a296cf8bc8b65ebf1af80cabe5ef077615af9962836a65ded0566a1aa850b-1245105309" style="color: rgb(255, 153, 0);"&gt;Koobface. NBO&lt;/a&gt;. This worm, detected nowadays by approximately 31 companies antivirus of 41 (75.61 %), on having infected the system establishes connection with the following URL's:&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;i&gt;http://oberaufseher.net/img/cmd.php &lt;/i&gt;&lt;br /&gt;&lt;i&gt;http://pornfat.net/img/cmd.php&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;It also downloads the following malware:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;TrojanDownloader.Small.OCS Troyano &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Tinxy.AD Troyano &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Tinxy.AF Troyano &lt;/i&gt;&lt;br /&gt;&lt;i&gt;BHO.NOE Troyano &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Koobface.NBH gusano &lt;/i&gt;&lt;br /&gt;&lt;i&gt;PSW.LdPinch.NEL Troyano&lt;/i&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/Spstvtm1LAI/AAAAAAAAAEA/Ca9K-VZUOCA/s1600-h/koobface-map.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/Spstvtm1LAI/AAAAAAAAAEA/Ca9K-VZUOCA/s320/koobface-map.gif" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;From the technical point of view, some data can be collected in the brief preliminary analysis of each of the malicious code downloaded by Koobface:&lt;br /&gt;&lt;br /&gt;The trojan &lt;a href="http://www.virustotal.com/analisis/5790fc5faf5091704c8bfd541166f91f7ae53a44c5c32e352cbb54cedf38f5b6-1245103923" style="color: rgb(255, 153, 0);"&gt;TrojanDownloader.Small.OCS&lt;/a&gt; has a detection rate of 35/40 (87.5%) creates keys in the registry and backs himself.&lt;span style="font-family:arial;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;HKLM\SOFTWARE\Microsoft\MSSMGR\&lt;/span&gt;  &lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\winccf32&lt;/span&gt;  &lt;span style="font-style: italic;font-family:arial;" &gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-style: italic;font-family:arial;" &gt;C:\WINDOWS\system32\winccf32.dll (&lt;/span&gt;copy of itself&lt;span style="font-style: italic;font-family:arial;" &gt;).&lt;/span&gt; &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/64d8a55d1473741dfba72090b3048b14ec3285f9c4937b4f1e1110770a59f82b-1245085742" style="color: rgb(255, 153, 0);"&gt;Tinxy.AF&lt;/a&gt;, another trojan, it also creates files in the system and has a detection rate of slightly less than the previous 30/40 (75.00%).&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;C:\windows\ld09.exe&lt;/span&gt;  &lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;C:\docume~1\user\locals~1\temp\podmena.bat&lt;/span&gt; &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; The trojan &lt;a href="http://www.virustotal.com/analisis/c5e963fe982ec0956e6d74cc2f598db5b255bf7f2ed24bee49640894e7722aa0-1245074104" style="color: rgb(255, 153, 0);"&gt;Tinxy.AD&lt;/a&gt; has a detection rate of 35/40, was detected by approximately 87.50% of the virus. Creates a copy of itself and makes use of the tool to enable a NetShell DLL, open ports, and specify a proxy.&lt;span style="font-family:arial;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;C:\WINDOWS\system32\SYSDLL.exe (&lt;/span&gt;copy of itself&lt;span style="font-family:arial;"&gt;)&lt;/span&gt;  &lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;netsh add allowedprogram "SYSDLL" C:\WINDOWS\System32\SYSDLL.exe ENABLE&lt;/span&gt;  &lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;netsh firewall add portopening TCP 80 SYSDLL ENABLE&lt;/span&gt;  &lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family:arial;"&gt;netsh firewall add portopening TCP 7171 SYSDLL ENABLE&lt;/span&gt;  &lt;span style="font-style: italic;font-family:arial;" &gt; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-style: italic;font-family:arial;" &gt;netsh winhttp set proxy proxy-server="http=localhost:7171"&lt;/span&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;span style="font-style: italic;font-family:arial;" &gt;Agrega la información del proxy en:&lt;/span&gt;&lt;span style="font-style: italic;font-family:arial;" &gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /d "http=localhost:7171" /f&lt;/span&gt; &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; &lt;a href="http://www.virustotal.com/analisis/f59756971261414efae9df3ad8772b3d3ea51f399a94deaa3969f3c510b9ed68-1245074096" style="color: rgb(255, 153, 0);"&gt;BHO.NOE&lt;/a&gt; is another of the trojans as part of the process of infection Koobface, with a detection rate of 92.11% (35/38), create a folder and a file.&lt;span  lang="EN-GB" style="font-family:arial;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span  lang="EN-GB" style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span  lang="EN-GB" style="font-family:arial;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span  lang="EN-GB" style="font-family:arial;"&gt;C:\WINDOWS\system32\796525&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;span  lang="EN-GB" style="font-family:arial;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span  lang="EN-GB" style="font-family:arial;"&gt;C:\WINDOWS\system32\796525\796525.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt; As to &lt;a href="http://www.virustotal.com/analisis/840dcf5b4e1c23e8aa75e6da77fe9ca697ceb599ec5a7e321dbee62328dfdc91-1245086434" style="color: rgb(255, 153, 0);"&gt;PSW.LdPinch.NEL&lt;/a&gt; trojan, detected by 34 antivirus of 40 (85.00%), is designed to steal passwords from different web browsers, mail clients, IM clients and other services.&lt;br /&gt;&lt;br /&gt;Finally, download a variant of the family, the worm &lt;a href="http://www.virustotal.com/analisis/6a88d6be2fadf3afbb86927d34e4da6f535700e5875db57864cd611ec51f578c-1245089677" style="color: rgb(255, 153, 0);"&gt;Koobface.NBH&lt;/a&gt;, in this case, the detection rate was 27/40 (approx. 67.50%).&lt;br /&gt;&lt;br /&gt;As we can see, the infection of this malware isn't just limited to malicious instructions they have, but it goes beyond that and download another. This action is a common behavior in the present, where the &lt;a href="http://mipistus.blogspot.com/2009/06/fusion-un-concepto-adoptado-por-el.html" style="color: rgb(51, 51, 255);"&gt;fusion of Web applications&lt;/a&gt; and control of botnets and the administration of different types of malware, joining forces with a common goal: improving the economics of crime.&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;via &lt;a style="color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/2009/06/symbiosis-malware-present-koobface.html"&gt;Pistus Malware Intelligence Blog&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;Malware Disasters Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2534927153970902867?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2534927153970902867/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/symbiosis-malware-present-koobface.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2534927153970902867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2534927153970902867'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/symbiosis-malware-present-koobface.html' title='Symbiosis malware present. Koobface'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sj6e71Uu06I/AAAAAAAABgg/VQ_YiCmmlAQ/s72-c/koobface.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-2716752160683191097</id><published>2009-12-05T15:20:00.000-08:00</published><updated>2010-03-01T17:49:03.402-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='adware'/><title type='text'>Swizzor reload. Adware and control of P2P networks</title><content type='html'>&lt;div style="text-align: justify;"&gt;P2P networks are one of the sources used to propagate different types of malicious code. That makes him very dangerous vector for those who don't take into account certain preventive measures.&lt;br /&gt;&lt;br /&gt;Moreover, the main function is to deploy adware popups displaying advertising without us even asking him many times after infection, it can display advertising even when a connection is made.&lt;br /&gt;&lt;br /&gt;This is an increasingly common case where different types of malware interact with each taking control of the computer to download and install additional malware.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Nomenclature: &lt;span style="font-weight: bold;"&gt;NSIS/TrojanDownloader.Swizzload.A&lt;/span&gt; (ESET)&lt;br /&gt;Md5: &lt;span style="font-weight: bold;"&gt;e2a2089255811ff295cdb695e426adc4&lt;/span&gt;&lt;br /&gt;Sha1: &lt;span style="font-weight: bold;"&gt;99eccdc87671138b9f4b15b0610bef8a3df418b6&lt;/span&gt;&lt;br /&gt;Report VirusTotal &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/a6d35e6fce4553534be3215165cb23c8384fcdb4dd784a428246e1c17f8b19f7-1260019479"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;15&lt;/span&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;/41 (36.59%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Packer: &lt;span style="font-weight: bold;"&gt;NSIS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It spreads through web pages using a strategy of social engineering. When run a number of file download from which there is an update of itself.&lt;br /&gt;&lt;br /&gt;From &lt;span style="font-weight: bold;"&gt;install.x3codec.com/get_file.php?file=program&amp;amp;program=codec_x3&lt;/span&gt; download:&lt;br /&gt;&lt;br /&gt;Nomenclature: -&lt;br /&gt;File: &lt;span style="font-weight: bold;"&gt;x3codec.exe&lt;/span&gt; located in &lt;span style="font-weight: bold;"&gt;codec_x3.zip&lt;/span&gt;&lt;br /&gt;Md5: &lt;span style="font-weight: bold;"&gt;06579ded81b2b648c5106d4732a4b06f&lt;/span&gt;&lt;br /&gt;Sha1: &lt;span style="font-weight: bold;"&gt;a2d05264eeb807e5fadd3bd60df3c0b6495c5a75&lt;/span&gt;&lt;br /&gt;Report Virus Total &lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/84c9664e269e63fbcf48e67c7544db11b3e412a84a207811ce2a1aa05152b0a5-1258280812"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;0&lt;/span&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;/41 (0.00%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Packer: -&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxrrNj5jLsI/AAAAAAAACAU/uwvkyHBkYDE/s1600-h/1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 180px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxrrNj5jLsI/AAAAAAAACAU/uwvkyHBkYDE/s400/1.png" alt="" id="BLOGGER_PHOTO_ID_5411896520446521026" border="0" /&gt;&lt;/a&gt;From &lt;span style="font-weight: bold;"&gt;install.x3codec.com/get_file.php?file=program&amp;amp;program=p2pc&lt;/span&gt; download&lt;br /&gt;&lt;br /&gt;Nomenclature: &lt;span style="font-weight: bold;"&gt;Trojan-Dropper.Agent&lt;/span&gt; (Ikarus)&lt;br /&gt;File: &lt;span style="font-weight: bold;"&gt;p2pc.exe&lt;/span&gt; alojado en &lt;span style="font-weight: bold;"&gt;p2pc.zip&lt;/span&gt;&lt;br /&gt;Md5: &lt;span style="font-weight: bold;"&gt;9964ee2867cb2128c8f3c84b311bdb86&lt;/span&gt;&lt;br /&gt;Sha1: &lt;span style="font-weight: bold;"&gt;a83edbe783856edf5c1838e2e1f9df9bca6ea6f2&lt;/span&gt;&lt;br /&gt;Report Virus Total &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/2d84774e25391d8587ee0cff3e655a27a61f095e6505d6bc7b1b7ac5b3f714a6-1259162310"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;3&lt;/span&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;/41 (7.32%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Packer: &lt;span style="font-weight: bold;"&gt;NSIS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Nomenclature: &lt;span style="font-weight: bold;"&gt;Downloader.Agent&lt;/span&gt; (Ikarus)&lt;br /&gt;File: &lt;span style="font-weight: bold;"&gt;VistaPutcher.exe&lt;/span&gt; alojado en &lt;span style="font-weight: bold;"&gt;p2pc.zip&lt;/span&gt;&lt;br /&gt;Md5: &lt;span style="font-weight: bold;"&gt;c899655cf6c26eadcd4f8adbc32d7da6&lt;/span&gt;&lt;br /&gt;Sha1: &lt;span style="font-weight: bold;"&gt;f316b3d09519cb73b512a58be6b7b688374839eb&lt;/span&gt;&lt;br /&gt;Report Virus Total &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/abed0fae00fa7bf06529eb8d4a53eae06a993e336be80ed2ba53f11b5769dee3-1259162319"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;9&lt;/span&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;/41 (21.95%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Packer: &lt;span style="font-weight: bold;"&gt;NSIS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrrUIY_yNI/AAAAAAAACAc/CuOhaJ8UzFM/s1600-h/2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 188px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrrUIY_yNI/AAAAAAAACAc/CuOhaJ8UzFM/s400/2.png" alt="" id="BLOGGER_PHOTO_ID_5411896633321310418" border="0" /&gt;&lt;/a&gt;After checking a number of information in the system makes the connection against connect.p2pcontrol.com/?command=install&amp;amp;uid={EE72CD72-7427-E246-A983-AF903B5DEC0E}&amp;amp;affid_tr=&amp;amp;os=XP where down the instructions to install the programs.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Sxrrc-d8AZI/AAAAAAAACAk/6wWhagaz1dU/s1600-h/3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 194px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Sxrrc-d8AZI/AAAAAAAACAk/6wWhagaz1dU/s400/3.png" alt="" id="BLOGGER_PHOTO_ID_5411896785276502418" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxrrk2cCdCI/AAAAAAAACAs/4lV1nEIpS70/s1600-h/4.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 312px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxrrk2cCdCI/AAAAAAAACAs/4lV1nEIpS70/s400/4.png" alt="" id="BLOGGER_PHOTO_ID_5411896920560006178" border="0" /&gt;&lt;/a&gt;The aim is to control the downloads through P2P networks by establishing a number of eDonkey servers and Kademila.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrrsJIzJvI/AAAAAAAACA0/PdhLcxdlF1Y/s1600-h/5.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 312px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrrsJIzJvI/AAAAAAAACA0/PdhLcxdlF1Y/s400/5.png" alt="" id="BLOGGER_PHOTO_ID_5411897045838669554" border="0" /&gt;&lt;/a&gt;From http://connect2.p2pcontrol.com/?command=download&amp;amp;filename=known_e.met establishes the following servers:&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="font-style: italic;"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;208.53.131.220:4662&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;208.53.131.221:4662&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;76.73.89.210:61895&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;208.53.131.220:27600&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;208.53.131.221:7258&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;76.73.77.66:52352&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;76.73.77.66:53352&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;208.53.131.221:4500&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;From&lt;span style="font-weight: bold;"&gt; install.x3codec.com/get_file.php?file=minime &lt;/span&gt;connects to http://space.cachefly.net/7714569/ and download the malware&lt;br /&gt;&lt;br /&gt;Nomenclature: &lt;span style="font-weight: bold;"&gt;a variant of Win32/TrojanDownloader.Swizzor.NCV&lt;/span&gt; (ESET)&lt;br /&gt;File: &lt;span style="font-weight: bold;"&gt;minime.exe&lt;/span&gt;&lt;br /&gt;Md5: &lt;span style="font-weight: bold;"&gt;898a21afe498579797e8bc8163f4b1e2&lt;/span&gt;&lt;br /&gt;Sha1: &lt;span style="font-weight: bold;"&gt;817f44e1fbf98f51f3266a35b246af757574ebd1&lt;/span&gt;&lt;br /&gt;Report Virus Total &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/62d657d93ee57ad0599ef06f5bc9f03f49e979e006be0895901ac342e61f1b1c-1259969225"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;22&lt;/span&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;/39 (56.41%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Packer: -&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;It also installs adware, responsible for changing the settings of Internet Explorer and Firefox through the following lines:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;[InternetExplorer]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;MinVersion=6&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HomePage=http://www2.iesearch.com/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;DefaultSearchEngine=Ask&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;SearchUrl=http://www2.iesearch.com/s/?q={searchTerms}&amp;amp;iesrc={referrer:source?}&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;GuidHash=x3Codec-search&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;[FireFox]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;MinVersion=2.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;HomePage=&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;DefaultSearchEngine=Ask&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;SearchUrl=http://www2.firesearch.com/s/?q={searchTerms}&amp;amp;src=FF-SearchBox&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxrsBkVPsDI/AAAAAAAACBE/g_fP4Of_xx8/s1600-h/search.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 246px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxrsBkVPsDI/AAAAAAAACBE/g_fP4Of_xx8/s400/search.png" alt="" id="BLOGGER_PHOTO_ID_5411897413915881522" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Some countermeasures&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li  style="font-family:courier new;"&gt;Uninstall programs &lt;span style="font-weight: bold;"&gt;Ask Search&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;P2PControl&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;x3Codec&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:courier new;"&gt;Delete the folders &lt;span style="font-weight: bold;"&gt;option bird&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;x3Codec&lt;/span&gt; located in the Program Files&lt;/li&gt;&lt;li  style="font-family:courier new;"&gt;Delete entry &lt;span style="font-weight: bold;"&gt;inside eggs&lt;/span&gt; located in the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Delete entry &lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;eggs joy math type&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; &lt;/span&gt;&lt;span id="result_box" class="short_text"  style="font-family:courier new;"&gt;located in the registry key&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxrsbi737pI/AAAAAAAACBM/GRbEWxkjrXw/s1600-h/registro1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 90px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxrsbi737pI/AAAAAAAACBM/GRbEWxkjrXw/s400/registro1.png" alt="" id="BLOGGER_PHOTO_ID_5411897860217630354" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrshPx7peI/AAAAAAAACBU/LRxdRkAFb1w/s1600-h/registro2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 90px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxrshPx7peI/AAAAAAAACBU/LRxdRkAFb1w/s400/registro2.png" alt="" id="BLOGGER_PHOTO_ID_5411897958154872290" border="0" /&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Delete the folder &lt;span style="font-weight: bold;"&gt;option bird&lt;/span&gt; located in X:\&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Documents and Settings\Administrator\Application Data. This folder contains the files:&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/ae2974f8565fbfc2b1bb6b3d1450273edbea3b6466ff095bc302d13f7bb95b16-1260050921"&gt; SEEKOWNSMETA.exe&lt;/a&gt; [&lt;span style="font-weight: bold;"&gt;a variant of Win32/TrojanDownloader.Swizzor.NDE Trojan&lt;/span&gt; (ESET)]. &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/296c66199a9085a567698ff048025ed3ab7338129dad91c911a70fe25209ac81-1260050957"&gt;borereadmebike.exe&lt;/a&gt; [&lt;span style="font-weight: bold;"&gt;a variant of Win32/TrojanDownloader.Swizzor.NCS Trojan&lt;/span&gt; (ESET)]&lt;/span&gt;.&lt;span style="font-family:courier new;"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt; &lt;/span&gt;&lt;a style="color: rgb(255, 153, 0);" href="http://www.virustotal.com/analisis/00020dd75da765a5fc9627abda38170609bae6b083d59313f3dbbf9fc89f6a69-1260051002"&gt;tfonuuvu.exe&lt;/a&gt; [E:\malware\not\tfonuuvu.exe - &lt;span style="font-weight: bold;"&gt;a variant of Win32/TrojanDownloader.Swizzor.NCY Trojan&lt;/span&gt; (ESET)]&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Restart your computer&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Delete the folder &lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;Bind army eggs joy&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; located in Documents and Settings\All Users\Application Data&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Change the start page in the browser and delete temporary files&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;Run your antivirus program updated&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Malware Disasters Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-2716752160683191097?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/2716752160683191097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/swizzor-reload-adware-and-control-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2716752160683191097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/2716752160683191097'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/swizzor-reload-adware-and-control-of.html' title='Swizzor reload. Adware and control of P2P networks'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxrrNj5jLsI/AAAAAAAACAU/uwvkyHBkYDE/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1670645896303580754.post-5396188428628406443</id><published>2009-12-01T15:17:00.000-08:00</published><updated>2010-03-01T17:48:02.609-08:00</updated><title type='text'>IMPORTANT READ</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Malware &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Disasters Team&lt;/span&gt; is comprised of a group of enthusiasts who are dedicated to the study and analysis of what computer security is known under the term "Malicious Code" (Malware).&lt;br /&gt;&lt;br /&gt;The intention is to concentrate in this space, a series of brief analysis, curiosities and manual disinfection proposals to help counter the negative effects that these types of threats caused by infecting a system.&lt;br /&gt;&lt;br /&gt;About proposals that seek to eliminate certain actions caused by an infection, we must bear in mind that the steps mentioned herein may change depending on the variant and family of malware, and from any point of view completely solves the problems that might have caused the infection.&lt;br /&gt;&lt;br /&gt;However, in complex problems where it isn't possible to access certain features of the operating system, the manual removal of certain harmful actions can help regain control of the system.&lt;br /&gt;&lt;br /&gt;On the other hand, also helps the study and understanding of the most common patterns that identify malicious activities and strategies different from malicious code.&lt;br /&gt;&lt;br /&gt;Accordingly, it leaves established that the contents of this site has as primary aim to provide the information necessary to understand how these threats and to act accordingly.&lt;br /&gt;&lt;br /&gt;The author also takes no responsibility for the misunderstanding that it could ever have of what transpired in this site, or the consequences which might arise in the implementation of countermeasures provided.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Malware Disasters  Team is a division of &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(255, 153, 0);" href="http://malwareint.blogspot.com/"&gt;MalwareIntelligence&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Malware Disasters  Team&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1670645896303580754-5396188428628406443?l=malwaredisasters.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwaredisasters.blogspot.com/feeds/5396188428628406443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/importante-leer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5396188428628406443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1670645896303580754/posts/default/5396188428628406443'/><link rel='alternate' type='text/html' href='http://malwaredisasters.blogspot.com/2009/12/importante-leer.html' title='IMPORTANT READ'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
