Friday, May 30, 2008
Tuesday, May 13, 2008
Thursday, May 01, 2008
Monday, April 07, 2008
Tuesday, April 01, 2008
Monday, March 31, 2008
Wednesday, March 19, 2008
Malware tampers with verclsid
Posted by
spywarebox
at
9:09 AM
0
comments
Monday, March 03, 2008
AVSystemcare, 5 star rating?
My PC gets infected with a Trojan which pushes the famous AVSystemCare rogue:
Very nice install screen!
Lots of happy customers:
It's MY DECISION!!!
Verdict:
A very good looking product with very bad intentions (your money).
Posted by
spywarebox
at
3:48 PM
0
comments
Thursday, February 28, 2008
When a picture hides an executable
A GIF file is harmless, right?
Wait, maybe not!
It turns out it's an EXE renamed just for the fun of it.
VirusTotal sneak preview:
Posted by
spywarebox
at
3:58 PM
0
comments
Wednesday, February 27, 2008
Trojans from China: exposed!
A nice collection of Trojans being pushed massively stored at:
down[hidden].china-s0ft.cn/downlist.txt
and more from another domain:
Posted by
spywarebox
at
3:53 PM
0
comments
Monday, February 25, 2008
Zlob Trojan: fake error, real infection
I found a fake video codec while doing some Google searches. It is very well crafted, with a bit of social engineering. At first I thought this one was VMware aware because of the error message. However, some deeper analysis revealed it was not. Some interesting things came up. Below is a summary.
Upon executing the sample, the following message shows up:
However, in the background things are taking place:
An Internet Explorer toolbar is created:
Only the following security vendors are detecting this threat at the time of posting:
Posted by
spywarebox
at
12:44 PM
0
comments
Thursday, February 21, 2008
Porn YouTube impersonation leads to malware

"Show Yourself"?
Once you pick a video, you are prompted to download a codec.
The site is totally bogus and the comments posted are fake (of course). Though kudos to whoever wrote them.
Installs a rogue app (VirusHeat) as well as a bunch of other bad stuff.
Posted by
spywarebox
at
1:21 PM
0
comments
Wednesday, February 20, 2008
Monday, February 18, 2008
Rogue infestation
A VM image infected with several rogue anti spyware apps. Note the antivirus.exe process (in Process Explorer). Although you see the process, the file is invisible to the system. Rootkit technique....
Also, one of the rogue is VM aware....




Posted by
spywarebox
at
11:19 AM
0
comments
Friday, February 15, 2008
Rootkit + Rbot Worm
I found something interesting while analyzing a malware sample.
A process called "taskmaneger.exe" was running (I can see it in Process Explorer). However it was not visible on the hard disk under its location System32.
I therefore rebooted under Linux (dual boot drive) and mounted the XP disk. I browsed it from Linux and this time I found the cuplrit classified as the Rbot Worm.
It is using Rootkit techniques to hide itself from Explorer, however, the process is still visible....
Posted by
spywarebox
at
12:27 PM
0
comments
Tuesday, February 05, 2008
Monday, January 21, 2008
Thursday, January 17, 2008
Malware AutoIt error
AutoIt is a program to write Windows scripts. This malware author didn't smoke test it well enough... it crashed on my machine as it was trying to do its payload.
Posted by
spywarebox
at
1:34 PM
0
comments



























