Archive for Spyware

Trust Cleaner, the rogue anti-spyware app that tricks you into thinking it’s Google.

A new rogue anti-spyware application has been released called Trust Cleaner. At first glance, this rogue anti-spyware application works the same way as the other ones that have been released lately like SpyFalcon and SpywareQuake as it uses trojans to display fake warnings that act as a goad to make you purchase the full commercial version of its software. This particular variant, though, adds some additional “features” to its installation that we will describe below. For those who are here because they are infected, and do not wish to read this entire article, you can visit our Trust Cleaner Removal Guide instead.

When the programs are installed on your computer, they are downloaded from the domain trustincash.com and trustcleaner.com. Both domains appear to use the domain registrar GoDaddy, but unfortunately, both domains are set as private so we can not determine any further information from the domain names about the people behind this malware. Both hostnames for the download sites, though, resolve to the same IP address so we know that they are running on the same web server and thus are most likely the same company. It is not surprising that we found that these IP addresses belong to the ISP Intercage who are notorious for hosting other malware and Spyware sites. We have purposely left out the specific urls that the infection uses to download its software from in order to protect our readers. If you are a security professional or security developer, please contact us to get this information.

After the malware is installed the rogue anti-spyware program Trust Cleaner is set to to start automatically when your computer starts. It then scans your computer for supposed Spyware and malware and displays a list of the items found. It is quite funny, though, as it finds its own components and labels them as Spyware as shown in the image below.

Trust Cleaner rogue anti-spyware program
Trust Cleaner Program

This infection, like all the other recent rogue anti-spyware apps, issues fake taskbar alerts by installing a DLL in your SharedTaskScheduler registry key that loads the DLL in either normal or safe mode. An example of a fake taskbar alert is below.

Trust Cleaner Fake Task Bar Alert
Fake Taskbar Alerts

This infection will also issue fake warnings on your desktop through the program C:\Program Files\TrustIn Popups\TrustInPopups.exe. This program will cause fake security warnings in the form of a Window directly on your desktop. An example of its fake desktop warning is found below. Another interesting feature of this program is it will cancel all Windows restart requests, effectively making it so you can’t restart your computer unless you kill the process first.

TrustInPopups.exe Fake Desktop Warning
Fake Desktop Warning Window

Furthermore, it will install a toolbar and other ActiveX controls in Internet Explorer that will present popups with “contextual” ads about various subjects you are searching for on other pages such as CNN, Yahoo, or Google among others. So if you go to the real Google site and search for something, this software will open a new Internet Explorer windows with its own ads that are specific to this search term. Although this malware alters the results of Yahoo and Google, it instead blocks all access to any web page in the MSN domain.

Finally and equally deceptive, it will change your Internet Explorer homepage to a html page that is loaded from a file on your local computer called C:\Windows\local.html. This page will generate a home page that looks strikingly like Google. In fact, it states at the bottom of the page that it is powered by Google. In reality, though, this page that actually uses results from the site www.mswindowssearch.com and not from Google. Below is an image of the fake home page and a real version of the Google home page so you can see the differences.

Trust Cleaner - Fake Google Homepage
Fake Google home page

Real Google Homepage
Real Google home page

Notice the copyright is significantly different from the one the Real Google homepage uses and there are different links on the main page? Let’s take a look at a search in the fake Google homepage using the search term job.

Fake Google Job Search
Fake Google search for the term Job

At first glance, the page looks a lot like a Google search result page. When you examine it close, though, you will notice quite a few differences. The main differences are that it does not allow you to go other pages in the results, has its own way of showing sponsored sites on the right side of the page, and displays very different results. Lets take a look at the same search using Google.

Real Jobs Search Using Google
Real Google search for the term Job

As you can see the format of the search results are almost identical, the page colors are the same, but the page layout is different. It is possible that this fake search engine is using the Google API to retrieve some of its results, as some of the results are legitimate and contain listing that you would think would not advertise with a Spyware company, but for the most part the results are typical for these types of hijackers.

As you can see this is a new breed of Rogue anti-spyware application. This variant is not satisfied with just try to scare you into purchasing a piece of software, now they are changing settings in Internet Explorer, displaying popups, and trying to cash in on the search engine advertisement market.

Tags: No Tags

Comments (6)

2 New SpywareQuake Variants - vhywj.dll & yfysupa.dll

Two new SpywareQuake variants found today: C:\Windows\System32\yfysupa.dll and C:\Windows\System32\vhywj.dll.

Reg keys for both files are as follows:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{cbb430e6-5b1b-474a-9d7e-160d4fe74bea}”=”feld”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{cbb430e6-5b1b-474a-9d7e-160d4fe74bea}\InProcServer32]
@=”C:\\WINDOWS\\system32\\yfysupa.dll”

And

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{a0aa3e4b-31cb-4ea2-9049-22b7f5b65edb}”=”fumarases”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{a0aa3e4b-31cb-4ea2-9049-22b7f5b65edb}\InProcServer32]
@=”C:\\WINDOWS\\System32\\vhywj.dll”

The SpywareQuake removal instructions have been updated for this varian

Tags: No Tags

Comments

New SpywareQuake Variant - ywbicim.dll

New SpywareQuake variant found today as well: C:\Windows\System32\ywbicim.dll.

Reg keys for C:\Windows\System32\ywbicim.dll:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{6c69e319-0d03-47da-997a-36586cbc53b3}”=”fortread”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{6c69e319-0d03-47da-997a-36586cbc53b3}\InProcServer32]
@=”C:\\WINDOWS\\system32\\ywbicim.dll”

The SpywareQuake removal instructions have been updated for this variant.

Tags: No Tags

Comments

New SpyFalcon variant

New SpyFalcon variant found today as well: C:\Windows\System32\higjxe.dll
Reg keys for C:\Windows\System32\higjxe.dll:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{a0c51615-738a-4542-801a-5af61614e182}”=”bedimples”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@=”C:\\WINDOWS\\system32\\higjxe.dll”

SpyFalcon removal guide updated.

Tags: No Tags

Comments

Three new SpywareQuake variants released.

This week the people who write SpyFalcon have instead focused on bringing out some new variants for SpywareQuake. As always the SpywareQuake removal instructions have been updated for these variants.
Reg keys for C:\Windows\System32\yhbdupd.dll:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{aea3d2df-2b2c-4d7b-81a0-d975c6dc088e}”=”alongshore”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{aea3d2df-2b2c-4d7b-81a0-d975c6dc088e}\InProcServer32]
@=”C:\\WINDOWS\\System32\\yhbdupd.dll”

Reg keys for C:\Windows\System32\imfdfcj.dll:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{e5b1e382-817e-4b74-8a96-ec78751e6acf}”=”incatenate”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
@=”C:\\WINDOWS\\system32\\imfdfcj.dll”

Reg keys for C:\Windows\System32\hvnwm.dll:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{62eb0924-19d2-4226-b4b9-8ad1f70904c1}”=”bronchovascular”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@=”C:\\WINDOWS\\system32\\hvnwm.dll”

Tags: No Tags

Comments

New SpyFalcon variant - bolnyz.dll

New SpyFalcon variant released: C:\Windows\System32\bolnyz.dll
Registry keys involved:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{f5947202-e9cb-4a72-88e7-22f2cbd2b124}”=”chenopodiaceae”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{f5947202-e9cb-4a72-88e7-22f2cbd2b124}\InProcServer32]
@=”C:\\WINDOWS\\system32\\bolnyz.dll”

SpyFalcon removal guide updated.

Tags: No Tags

Comments

Two more SpyFalcon variants

Two more variants:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{5bc82bdb-bc03-4671-9a78-3ef2b68449de}”=”advisability”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{5bc82bdb-bc03-4671-9a78-3ef2b68449de}\InProcServer32]
@=”C:\WINDOWS\system32\oqipt.dll

and

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{70fbd528-2d3c-4a00-9b8c-bbf441e534be}”=”AutoDisc Ware”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{70fbd528-2d3c-4a00-9b8c-bbf441e534be}\InProcServer32]
@=”C:\WINDOWS\System32\iqzv.dll

SpyFalcon removal guide updated.

Tags: No Tags

Comments (1)

SpyFalcon hits again..3 new variants in one day.

Another new SpyFalcon variant.  Anyone else getting bored of all of these?

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{a566f298-05a6-4b3d-b672-da7c27316430}”=”AutoDisc Ware”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
@=”C:\WINDOWS\system32\htey.dll”

SpyFalcon removal guide updated.

Tags: No Tags

Comments

New SpyFalcon Variants

Two new variants of SpyFalcon have been released.  The SpyFalcon removal guide has been updated to reflect these new variants.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{89aef01d-d237-49c7-84dc-4e1904c1fd31}”=”AutoDisc Ware”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{89aef01d-d237-49c7-84dc-4e1904c1fd31}\InProcServer32]
@=”C:\WINDOWS\system32\sbnudh.dll

and

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{e04408db-4812-4478-8d4d-e46edcffd3b6}”=”AutoDisc Ware”

[HKEY_CURRENT_USER\Software\Classes\CLSID\
{e04408db-4812-4478-8d4d-e46edcffd3b6}\InProcServer32]
@=”C:\WINDOWS\system32\fyhhxw.dll

Rumors are that the  C:\WINDOWS\system32\fyhhxw.dll  infector has randomly changing CLSID.

Tags: No Tags

Comments

Removal guide for Spyware Sheriff and the Antispylab.com

Spyware Sheriff and the Antispylab.com infections are starting to get decent visibility in many of the antimalware forums.  Due to this demand we have put together a detail guide on the removal of this infection.  This guide can be found here:

How to remove Spyware Sheriff and Antispylab

Tags: No Tags

Comments

« Previous entries ·

Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides


© 2003-2008 All Rights Reserved Bleeping Computer LLC.

Featured Microsoft Expert Zone Community