Tuesday, May 13, 2008
Thursday, May 01, 2008
Monday, April 07, 2008
Tuesday, April 01, 2008
Monday, March 31, 2008
Wednesday, March 19, 2008
Malware tampers with verclsid
Posted by
spywarebox
at
9:09 AM
0
comments
Monday, March 03, 2008
AVSystemcare, 5 star rating?
My PC gets infected with a Trojan which pushes the famous AVSystemCare rogue:
Very nice install screen!
Lots of happy customers:
It's MY DECISION!!!
Verdict:
A very good looking product with very bad intentions (your money).
Posted by
spywarebox
at
3:48 PM
0
comments
Thursday, February 28, 2008
When a picture hides an executable
A GIF file is harmless, right?
Wait, maybe not!
It turns out it's an EXE renamed just for the fun of it.
VirusTotal sneak preview:
Posted by
spywarebox
at
3:58 PM
0
comments
Wednesday, February 27, 2008
Trojans from China: exposed!
A nice collection of Trojans being pushed massively stored at:
down[hidden].china-s0ft.cn/downlist.txt
and more from another domain:
Posted by
spywarebox
at
3:53 PM
0
comments
Monday, February 25, 2008
Zlob Trojan: fake error, real infection
I found a fake video codec while doing some Google searches. It is very well crafted, with a bit of social engineering. At first I thought this one was VMware aware because of the error message. However, some deeper analysis revealed it was not. Some interesting things came up. Below is a summary.
Upon executing the sample, the following message shows up:
However, in the background things are taking place:
An Internet Explorer toolbar is created:
Only the following security vendors are detecting this threat at the time of posting:
Posted by
spywarebox
at
12:44 PM
0
comments
Thursday, February 21, 2008
Porn YouTube impersonation leads to malware

"Show Yourself"?
Once you pick a video, you are prompted to download a codec.
The site is totally bogus and the comments posted are fake (of course). Though kudos to whoever wrote them.
Installs a rogue app (VirusHeat) as well as a bunch of other bad stuff.
Posted by
spywarebox
at
1:21 PM
0
comments
Wednesday, February 20, 2008
Monday, February 18, 2008
Rogue infestation
A VM image infected with several rogue anti spyware apps. Note the antivirus.exe process (in Process Explorer). Although you see the process, the file is invisible to the system. Rootkit technique....
Also, one of the rogue is VM aware....




Posted by
spywarebox
at
11:19 AM
0
comments
Friday, February 15, 2008
Rootkit + Rbot Worm
I found something interesting while analyzing a malware sample.
A process called "taskmaneger.exe" was running (I can see it in Process Explorer). However it was not visible on the hard disk under its location System32.
I therefore rebooted under Linux (dual boot drive) and mounted the XP disk. I browsed it from Linux and this time I found the cuplrit classified as the Rbot Worm.
It is using Rootkit techniques to hide itself from Explorer, however, the process is still visible....
Posted by
spywarebox
at
12:27 PM
0
comments
Tuesday, February 05, 2008
Monday, January 21, 2008
Thursday, January 17, 2008
Malware AutoIt error
AutoIt is a program to write Windows scripts. This malware author didn't smoke test it well enough... it crashed on my machine as it was trying to do its payload.
Posted by
spywarebox
at
1:34 PM
0
comments
Thursday, January 10, 2008
MSN Worm
The worm propagates from System to System by downloading an infected Zip file and sending it to all your contacts in MSN.

Posted by
spywarebox
at
3:54 PM
0
comments
Friday, January 04, 2008
Facebook Phishing Scam
This domain is hosted in China and pretends to be the Facebook login page.
Fiddler transcript below. It captures your email address and password and sends it over. After that, it redirects you to the legit Facebook page where you are prompted again to enter your credentials.
Posted by
spywarebox
at
9:39 AM
0
comments
Tuesday, December 11, 2007
Wednesday, November 28, 2007
Friday, November 09, 2007
Monday, November 05, 2007
Friday, November 02, 2007
Monday, October 29, 2007
Friday, October 26, 2007
Thursday, October 18, 2007
PrivacyProtector's provocative ad
How far are rogue programs going to go to convince you?
This is shocking, showing you real porn pictures that you may have on your computer.
Posted by
spywarebox
at
3:26 PM
0
comments
Monday, October 15, 2007
Friday, October 12, 2007
Storm Worm rootkit

Posted by
spywarebox
at
11:48 AM
0
comments
Tuesday, September 25, 2007
Part of a Botnet
After running a Trojan, I checked the network traffic for communications with the outside.
The Trojan was reporting the name of my computer and other info to a web server... The kind of stats a bot herder might use...
Posted by
spywarebox
at
3:49 PM
0
comments
Live Messenger infection
Running Live Messenger with a lot of (unknown) contacts can be a dangerous thing:
First a window pops up. It's not a good sign when I haven't touched my browser:
A quick glance at Process Explorer confirms the infection:
Posted by
spywarebox
at
3:40 PM
0
comments
Thursday, September 20, 2007
Tuesday, September 18, 2007
Wednesday, September 05, 2007
PornTube... dangerous fake codec
Watch out for this YouTube imitation... Nasty Trojan when you download a video.
New Zlob fake codec site: hxxp://zero-codec.com
Posted by
spywarebox
at
11:26 AM
0
comments
Tuesday, September 04, 2007
Porn pop up leads to Zango's website
Ran a Trojan that created a pop-up designed to ressemble Youtube videos. On click, you are redirected to Zango's website.
Posted by
spywarebox
at
12:12 PM
0
comments
Thursday, August 30, 2007
Well crafted IM Worm
I came across an interesting IM Worm today:
First, I get this IM with a link to follow:
It brings me to this website, that, for some reason ;-), needs me to install the Flash player:
Surprisingly, this "Flash Player" is infected!!!
In case, I didn't download the file, the webpage itself has a malicious and obfuscated code that pushes the installer down my throat:
And to finish the loop, it sends out Instant Messages in my name to all the people on my contact list (to spread the word I suppose).
Posted by
spywarebox
at
3:24 PM
0
comments
Wednesday, August 29, 2007
Fake Google site
Drive-by exploit launches when you visit this site. If you use Firefox they trick you into downloading an add-on.
Another point of interest, clicking on the Sign in link will open the AdultFriendFinder website. Oops..
To avoid this, check out the URL in the address bar. It is not Google's. Also, Google will never ask you to download additional software to do a search. At least, not right now.
Also, drag your mouse onto the links on the page, and you may see in IE's status bar, that they point to a totally different site.
Posted by
spywarebox
at
10:43 AM
0
comments
Wednesday, August 22, 2007
Monday, August 20, 2007
Interesting MSN stuff
This user's display name is "DO NOT ACCEPT FILES FROM ME".... Well, it makes sense since it is trying to send me some infected files... But still, rather odd.
This one likes to send pictures and other stuff... even after the first No, they continued... Of course, these files are dangerous to open.
Posted by
spywarebox
at
10:11 AM
0
comments



























































