1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Two Infections For The Price Of One

Discussion in 'Security Updates' started by starbuck, Jan 14, 2011.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    2GCash and Windows System Optimizator rogue from one fake codec scam.

    Today we came across this fake codec scam that delivered two pieces of malware for those unfortunate enough to stumble across it. The malicious site offers Megan Fox and Carmen Electra sex videos (among other things.)

    [​IMG]

    After installing a fake video viewer, it throws up fake Microsoft Security Essentials alerts and installs the Windows System Optimizator rogue.

    [​IMG]

    [​IMG]

    [​IMG]

    # 1. 2GCash (VIPRE detection: VirTool.Win32.Obfuscator.hg!b1)

    The 2GCash malware has been one of the major downloaders. It’s been used by thousands of affiliate sites since 2008. Its main purpose is to generate profits through click fraud transmissions from infected computers and search engine result hijackings.

    VIPRE detects the 2GCash malware as VirTool.Win32.Obfuscator.hg!b1 (v). Kaspersky detects it as *.codecpack, Sophos as FakeAV-CX and Microsoft as Renos.

    It uses online scanner scams, third party bundled downloads, fake codec scam sites and fake crack serial sites.

    The file video_part_##.exe is detected as Trojan.Win32.Generic.pak!cobra

    # 2. Windows System Optimizator rogue

    Windows System Optimizator is a rogue what uses a fake Microsoft Security Essentials alert. VIPRE detects it as Trojan.Win32.Generic.pak!cobra.

    It’s a rebranding of the Windows Optimization Center rogue.

    2GCash

    2GCash is the name we gave the detection when the group behind it began an affiliate program with a site named go-go-cash.com in December of 2008.

    The page for affiliates was titled "Go Go Cash."

    [​IMG]


    Source:
    http://sunbeltblog.blogspot.com/2011/01/two-infections-for-price-of-one.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SunbeltBlog+%28GFI+Blog%29
     
  2. Match

    Match Registered Members

    Joined:
    Apr 23, 2009
    Messages:
    4,175
    Location:
    Wolverhampton, UK.
    Computer Brand or Motherboard:
    Abit AN52
    CPU:
    AMD Athlon dual core 5000+
    Memory:
    4 Gig Corsair
    Hard Drive:
    160 Gb Hitachi 500 Gb Western Digital
    Graphics Card:
    Radion XFX 4650
    Power Supply:
    550W EZcool
    LOL Malware Marketing, I know using sex to sell infections is nothing new but now they are doing BOGOF (Buy one get one free) offers, next they will be offering interest free credit as well :snckr:

    But seriously

    Thanks for the Heads Up :D
     
  3. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hadn't thought of it that way. :)
    These guys will try every trick in the book, plus a few that are not written yet.
     

Share This Page