Results 1 to 3 of 3
  1. #1
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879

    A chameleon rogue

    After reading this, my reaction was Holy crap!!! I think we will expect to see more of this kind of rogues in the future.

    We all know that fake antivirus solutions trick users into downloading a product by showing alarmist pop-ups claiming that the PC is packed full with malware. This one takes things to a whole new level. It starts by displaying personalized warning message windows that are strikingly similar to the AV solution it finds installed on the system. Yes, it is a chameleon that has a copycat kit for all the important AV products on the market. It goes so far in that it initially determines the AV running on the machine and the interface language selected by you. It will afterwards use the captions, the icons and the messages consistent with the personalized settings of the installed AV.

    In order to leave you totally unprotected, the Trojan displays a popup warning and kindly asks you to reboot the system in order to perform the clean-up. But, before that, it queues your antivirus for uninstallation, then uses the genuine Microsoft bcdedit.exe (command line tool for managing BCD (Boot Configuration Data) files) in order to instruct the system to boot in safe mode after restart.

    An eg.

    Source and more info : http://www.malwarecity.com/blog/troj...vies-1114.html

    But there is still a way to beat it. It requires CURIOSITY of a user WITHOUT the PROPER KNOWLEDGE.
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  2. #2
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Thank you LunarWolf this is taking it to a whole new level, worthy of mentioning it here for us to take alook at what is happening... clever in the wrong way..
    Stutz Bearcat

  3. #3
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks a lot for the warning LunarWolf! I come across this kind of crap ocassionally and I can easily see how the unwary could be trapped by it.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

 

 

Similar Threads

  1. Replies: 5
    Last Post: 03-09-2011, 09:49 AM
  2. Chameleon Window Manager 1.1.0.120
    By Boyfriend in forum Latest Releases
    Replies: 0
    Last Post: 12-21-2010, 09:06 PM
  3. Chameleon Window Manager
    By ha14 in forum Latest Releases
    Replies: 3
    Last Post: 11-05-2010, 10:56 PM
  4. Chameleon Startup Manager (GAOTD)
    By boz1972 in forum Freebies!
    Replies: 4
    Last Post: 10-24-2009, 08:40 AM
  5. Rogue
    By AlanH in forum Spyware/Viruses
    Replies: 10
    Last Post: 02-21-2009, 06:19 PM
All times are GMT +8. The time now is 09:54 AM.