| Category |
 |
Fake
Anti Spyware |
| Discovered |
|
7/4/2008
09:49:00 AM |
| Modified |
|
7/4/2008
10:49:00 AM |
| Threat
Level |
 |
Critical |
| Description |
 |
WinAntispyware2008
is a new Fake Anti
Spyware program.
WinAntispyware2008
displays misleading
information to scare
the user into purchasing
their software.
WinAntispyware2008
is advertised through
web sites pretending
to scan user computer
for infections.
When these fake
scans are done,
it state user computer
is infected. WinAntispyware2008
opens the fake alert
messages. |
| Summary |
 |
The
hosts file was updated
with the following
url-to-ip mappings
: n/a The
following http urls
were started :
n/a Generated
smtp traffic :
n/a There
was a new connection
established with
a remote IRC Server
: n/a The
Following Hidden
Entries Created
: n/a The
following internet
connection was established:
n/a |
| Processes |
|
WinAntispyware2008.exe |
| Drivers |
|
N/A |
| Folders
created |
|
%PFDIR%\WinAntispyware2008
%PFDIR%\WinAntispyware2008\data
%COMMON_PROGRAMS%\WinAntispyware2008 |
| Browsed
Sites |
|
http://winantispyware2008.com/download.html |
| When
the Fake Anti Spyware
is executed, it
creates the following
files: |
| Name |
Version |
Publisher |
Signature
(MD5) |
File
Size (in Bytes) |
| ..\quick
launch \winantispyware2008.lnk |
|
|
|
1552 |
| ..\winantispyware2008
\htmlayout.dll |
|
|
818ee10d4350f8c2ad9e5ec223aa7c0c |
|
| ..\winantispyware2008
\winantispyware2008.exe |
1.0.0.1 |
|
06ace575bd8f66c26320e8bd1d92a39f |
531100 |
| ..\install.exe |
1.0.0.1 |
|
fb44bede43cfdaaa646d0216572b4a9b |
56924 |
| ..\desktop\winantispyware2008.lnk |
|
|
|
1552 |
|
|
| When
the Fake Anti Spyware
is executed, it
creates the following
Registry entries: |
| • |
..\software\microsoft\windows\currentversion\run\"winantispyware2008" |
| • |
..\software\microsoft\windows\currentversion\uninstall\winantispyware2008 |
| • |
..\software\winantispyware2008 |
|
Snapshot
 |