This is cache of http://blog.spywareguide.com/2008/07/malware-install-hides-behind-f.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
Malware Install Hides Behind Fake Blue Screen Of Death
2008-07-09 18:42:24 by Christopher Boyd in SpywareGuide Greynets Blog
 
This hijack typically begins with the following file opened up from the web:

sys0.jpg


If the file is allowed to execute on the PC, depending on what files the bundle is rotating for download at the time of install you may well see the dreaded Blue Screen Of Death (or BSOD to its friends).

However, all is not what it seems. While the end-user is faced with the horrors of the BSOD, behind the scenes Malware is installing by the bucketload.How is this possible, I hear you cry? Surely if the PC has crashed, nothing can be installing?

Not in this case, because the blue screen of death is fake - to be more accurate, the bad guys have taken Sysinternals blue screen of death screensaver and bundled it in with the hijack files. This is what the .scr file looks like on the PC:

sys1.jpg


And this is what you see if you explore the code:

sys2.jpg


It seems the bad guys are not without a sense of humour. Hiding a blizzard of infection file installs behind a legitimate screensaver created by a security expert is pretty bizarre. Here is the registry entry created:

sys6.jpg

Meanwhile, here are just some of the files installed onto the PC during the download:

sys5.jpg

Click to Enlarge

The PC pretty much grinds to a halt while all of this is taking place:

sys7.jpg


When the computer finally comes back under your contol, you can expect to see numerous warnings related to fake antispyware programs appearing all over the desktop:

sys8.jpg

Click to Enlarge

sys9.jpg

Click to Enlarge

sys10.jpg


Collectively, we detect the various bundles on offer here as Fake.AV and Smiddy.

Discovery and Research: Chris Mannon, FSL Senior Threat Researcher
 
 
 
 
 
 
TOP SEARCH
Expand / MinimizeClose Widget
  •  
RECENT SEARCH
Expand / Minimize
  •  
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia