Posted on 15-12-2008
Filed Under (Uncategorized) by admin
rjcuk asked:


Video download from http://www.websense.com/videos/seclabs/wmf-movie.wmv showing a real-time infection of a spyware trojan on a computer caused by visting a website that hosts a spyware installer.

This is just a demonstration of how dangerous spyware is if you don’t have the right protection software installed. The computer was more than likely wiped and formatted after being at the mercy of this infection.

If you can’t see the video well, this is what it does:

1) The user who is controlling the computer types in a website address into Internet Explorer and hits enter. The file he downloads automatically opens up and starts opening up with Windows’ Picture viewer – but the file he download wasn’t a picture.
2) Immediately the file runs a batch command (the black screen) which is basically like an installer for the virus. Suddenly a whole load of new icons appear on the desktop.
3) An icon also appears in the system tray and the balloon tip says “Your computer is infected!”. In fact, this is not a message from the Windows OS, but it is a fake message from the virus that asks the user to run a fake anti-virus software to “remove” it from your computer. In actual fact, the message is true, but what users don’t realise is that the message itself is the virus.
4) Suddenly the desktop changes (you notice by now that the computer is running much slower due to the virus infecting the whole computer) to a picture the virus put on there.
5) A new icon appears on the desktop called WinHound and the program starts running (you can see the splash page with the picture of the leopard/tiger).
6) WinHound then “pretends” to scan the computer for viruses and it makes a lie about there being a different virus on the computer. It makes the user think that WinHound is an antivirus product by scanning the computer, but it actually isn’t.
7) When the scan is complete a dialog appears (notice that it’s called “Microsoft Internet Explorer” :D ) that tells the user there is a “fake” infection. 8) Another dialog is opened up which asks the user to visit a website where they can “pay” for a removal tool for the “fake” virus. In fact, the website is actually a phishing website which asks for credit card details. This makes the user think that they have to pay for a removal tool, but what they actually get is their money stolen.

Just so you know, this is *not* my own video. I did not create it. I downloaded it from the link above. My own computer is perfectly fine, thank you!

Custom rims wholesale…instantly.

Sphere: Related Content

(0) Comments    Read More   

Comments

STAYTOONED2ME on 18 December, 2008 at 7:49 pm #

if you get this, your doomed


majingoku96 on 20 December, 2008 at 1:17 pm #

i had that once a caution was on the desktop and it wanted me to install some virus remover thing……ya right


ihatemylife64 on 21 December, 2008 at 4:34 pm #

yes, a bad one


maryhousel on 23 December, 2008 at 1:26 pm #

is winhound a rouge anti virus?


Pixelize45 on 25 December, 2008 at 4:46 am #

I had that shit, source is file named BRASKT.EXE
located in system32 dir.
Try firstly kill process called braskt, then remove file.


seesawss on 28 December, 2008 at 8:16 am #

wait i think mine just went away

nope it didnt how do you get it to go away


Kirov1234 on 30 December, 2008 at 9:48 pm #

i think you need to install your whole computer again if you get this D:


unusualcatperson on 1 January, 2009 at 5:23 pm #

This isn’t his video, so you don’t have to ask, do you?


bigbang99101 on 3 January, 2009 at 12:22 am #

dude u had the yur virus first go ctrl alt delete then go to processes tab then end the processs yur one and yur2 next dowload MALWAREBYTES the most safe download is on cnet malwarebytes will quarantine the virus and you are good to go that is what i did and it worked great


slaterking1000 on 3 January, 2009 at 4:34 am #

Will AVG internet security remove this porgram?


ToastedDinner on 5 January, 2009 at 1:56 pm #

A simple use of AVG, Ccleaner and Spybot removed this!
Mine was diffrent, unlike the video, i had *** **** ****** icons all over my desktop, and ran them..
Oh, i vomited.


nightmare1alphat07 on 5 January, 2009 at 5:22 pm #

can i put this vid on my web

permission


nubcake531 on 8 January, 2009 at 1:35 am #

use smitfraud fix and then use combofix


unusualcatperson on 9 January, 2009 at 10:30 pm #

What I had to do was I had to back up all of the files (by putting them on an external hard drive) then totally reset (not restart) your computer. But you might wanna run spybot or something. DOn’t run any of the false virus protections that smitfraud downloads itself. If any new icons just suddenly appear, and your computer is running slow or something that a virus would do, DO NOT touch them. Just leave them be. Good luck.


superslayer626 on 11 January, 2009 at 10:55 am #

well u may have it firgured out already but if u dont search smitfraud fix on google and it will come up with a few sites on how to fix it


yevgeniyboy on 12 January, 2009 at 8:29 am #

plz guys i beg u i need ur help i have same problem when i turn on it changes background to danger and its messed up how do i make it go away my bro will kill me plz guys i realy need ur help


dinnnnm on 14 January, 2009 at 2:42 am #

ihave files in my computer named
spysheriff fake adware
and
smitfraud -c or whatever it said wheni scan for spyware and i have no viruses in computer but theres files named that
is that just files in computer named those?
avast dont find no virus and these files bin in for year or 2 but no problems in computer


f0rgotmyname on 15 January, 2009 at 11:05 pm #

DAMN straight,tell them like it is :D


gmoney101392 on 18 January, 2009 at 7:20 pm #

CAN SOMEONE HELP ME this is kinda what i have, but no windhound, i have trend micro antivirus and spy sweeper and pc tools antivirus, they find stuff i quarintine and delete it, but the things are still there, computer still slow, viruses keep comming back., still cant change wallpaper


shadowfist39 on 21 January, 2009 at 3:38 am #

no its not for big boys google you tube and it will say for all ages


cadefulp on 21 January, 2009 at 9:26 pm #

GTFO you fucker


oconnell999 on 24 January, 2009 at 11:33 am #

do a full system restore if thats no good reinstall windows


thequickspin on 24 January, 2009 at 1:49 pm #

@PSPGamer120: It sounds like a bad case of spyware. I’d recommend going to wikipedia and look up smitfraud removal. That’s where I found a smitfraud tool.

From there you’ll search your way through to a website offering smitfraud removal, which gets rid of that fake “your computer is infected” nonsense.

Also, what is the name of your anti-virus or anti-spyware you’re using? Chances are your anti-spyware is what’s doing it, if it’s fake.


MUHAHAHA555 on 25 January, 2009 at 4:51 pm #

Agreed. How come replys do not go under the original post? I am replying to thequickspin


Post a Comment
Name:
Email:
Website:
Comments: