Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 19th, 2010, 09:59 GMT · By

New Koobface Variant Installs Highly Invasive Rogueware

SHARE:

Adjust text size:


Koobface installs 'AV Security Suite' rogueware
Enlarge picture
Security researchers warn that the latest Koobface variant drops a scareware program, which severely impacts the victim's ability to use the infected system. The application, which poses as an antivirus, makes Web browsing impossible and prevents almost all programs from running.

Koobface is a computer worm, which spreads on social networking websites. It was originally created for MySpace, but it now targets users of many such sites, including Facebook, Twitter, hi5, Bebo and Friendster. The worm relies heavily on social engineering to lure people onto malicious pages and infect them.

The attack normally starts with spam messages about interesting videos, which contain links to external page. These external sites regularly mimic YouTube, and present users with fake alerts claiming a special codec or a Flash Player update is required to see the video.

Of course the executable file served for download is actually the installer of the worm, which once installs proceeds to send email spam from the infected computer. It also steals the victim's social networking login credentials and uses them to post rogue message from their profiles.

Screenshot of 'AV Security Suite' scareware
Enlarge picture
Several weeks ago Koobface added DNS hijacking functionality that blocks access to security sites, tipping users off to the fact that something might be wrong with their systems. Since then the authors have taken a giant leap toward invasiveness with the installation of a fake anti-virus Trojan,” security researchers from McAfee warn.

The rogue program is called “AV Security Suite” and bombard users with fake security alerts about fictitious infections. This is not unlike other programs in the FakeAV family, however this application borders on ransomware.

First, it installs a local HTTP proxy and forces all browser requests to pass through it. This prevents users from accessing any website and instead they see a page displaying a bogus security warning instructing them to purchase a license for the rogue security software.

Opening executable files is also blocked and will generate a similar warning, requesting immediate activation of the program. As always, users are advised to exercise caution when choosing to visit links spread on social networking websites and never surf the Web without an up-to-date antivirus installed.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,659 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Obscene Ukrainian Ransomware in the Wild

New Scareware Leverages the Layered Service Provider

New Koobface Campaign Spotted on Facebook

TweetMeme Hit by Malvertisement

Latest BHSEO Attacks Use Fake YouTube Pages and Flash Player Updates

READER COMMENTS:


Comment #1 by: Cleaner on 21 Jul 2010, 21:34 UTC reply to this comment

Actually AV Security Suite can be cleaned using Malwarebytes AntiMalware.
Just start the system in safe mode,change the Internet settings made by the rougueware and then go to Malwarebytes site.From there download and install Antimalware,scan.Finally remove the crap!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM