MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.

8.29.2010

Litter Korean rogue lurking V

Another piece of rogue from Korea and belonging to the family of PrivacyKeep, PrivacyCorp and PCScan.

ProtectInfo

protectinfo.co.kr - 114.108.168.8 - DACOM-NET LG DACOM


The IP address also resolves the following domains:
ad-clear.com
privacycop.co.kr
privacykeep.co.kr
protectinfo.co.kr

protectinfo_home.exe (a48e62c64f68a2b32dc601efffa2973d)

update.protectinfo.co.kr/instchk.php

226
[COUNTER]
NUM=6

[CHECK1]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK2]
HKEY=HKLM
REGPATH=PrivacyCheck
REGNAME=DisplayName
REGVALUE=.......... ....

[CHECK3]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK4]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK5]
HKEY=HKLM
REGPATH=..........
REGNAME=DisplayName
REGVALUE=..........

[CHECK6]
HKEY=HKLM
REGPATH=privacykeep
REGNAME=DisplayName
REGVALUE=............

[HISTORYREG]
PATH="............"


protectinfo.co.kr/app_linkage/app_install.php?addr=000C29CA888C&ptn=infocode0067
protectinfo.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C

3d
payed=0
pw_usr=
pw_sup=1470
hp1=
hp2=
hp3=
small=300
big=300


log.adsence.co.kr/logexp.php?aid=protectinfo&pid=infocode0067&kind=inst
file.protectinfo.co.kr/update.php

protectinfo.exe=0.325
pnfoupdater.exe=0.113
pnfohk.dll=0.110
pnfouninst.exe=0.1
pnfowcher.exe=0.116
pnfopopd.dll=0.1


protectinfo.co.kr/app_linkage/app_boot.php?ver=.0.398
protectinfo.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C
protectinfo.co.kr/settlement/paysys/mobile/Deliver.php
protectinfo.co.kr/settlement/paysys/pbill/Deliver.php
protectinfo.co.kr/settlement/paysys/ars/Deliver.php



Countermeasures

Uninstall from Program Files
Running updated antivirus

Related information



Litter Korean rogue lurking IV
Litter Korean rogue lurking III
Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Jorge Mieres 

Ver más

8.22.2010

Litter Korean rogue lurking IV

Korean rogue fourth part of the "litter" that haunts the past few days looking for potential victims caught in Korea. At times the rogue that spread can have an option to change the language, so that coverage is much wider infection, however, in this case, it's directed at specific populations rogue.

PrivacyCorp
privacycop.co.kr - 114.108.168.8 - DACOM-NET LG DACOM


The IP is also the following domains:
ad-clear.com
info-dr.com

privacycop_setup.exe (8362c089bc4f7932dc885e23044cb2f6)
privacy_mediccop.exe (46f2a84d7217a5ca56208ea0b13c6f52)

The circuit is part rogue criminal systems led by members who pay a percentage of money for each installation of the threat spread. This case is no exception. The rogue reports successful installation immediately after infection.

privacycop.co.kr/app_linkage/app_install.php?addr=000C29CA888C&ptn=home
log.adsence.co.kr/logexp.php?aid=privacycop&pid=home&kind=inst
privacycop.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C
3e
payed=0
pw_usr=
pw_sup=1470
hp1=
hp2=
hp3=
small=300
big=3660

file.privacycop.co.kr/update.php
6d
privacycop.exe=0.328
pvcupdater.exe=0.112
pvchk.dll=0.1
pvcuninst.exe=0.1
pvcwcher.exe=0.112
pvcpopd.dll=0.1

privacycop.co.kr/app_linkage/app_boot.php?ver=.0.4.5.3
privacycop.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C


Countermeasures
Terminate the processes called privacycop.exe and pvcwcher.exe. You can use the ProcessExplorer to view and terminate processes.

Uninstall from Program Files
Running updated antivirus

Related information

Litter Korean rogue lurking III
Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

Litter Korean rogue lurking III

PCScan is another rogue Koreans that have appeared in recent days, in addition to the two previously showed.

pcscan.kr - 114.108.129.233 - DACOM-NET LG DACOM

The IP also resolves the following domains:
eroza.net
master.to84.net
to84.net
www.tvbaro.net

Setup.exe (a85900759318ea66dc94ba789aae2cfe)
PCScan.exe (665b846b82d959843744d9d3a7b39bdc)
PCScanMon.exe (01cdb8f8955a4df6eebb1aca04d6a43c)
Uninstall.exe (76cd1340bded9d96050df30999f6274d)

Unistaller.exe file simulates the uninstaller antivirus program assumes, however, no effect arises because it’s false.

Check the following pages:
pcscan.kr/request/module_setup.php?p=PCScan&a=type1
pcscan.kr/request/License.txt
pcscan.kr/down/install.exe
down.elineguide.com/down/install.exe

pcscan.kr/down/files.php?strMode=setup&strID=PCScan&arg=type1&strSite=&strPC=000c29ca888c
pcscan.kr/down/PCScan.exe
pcscan.kr/down/PCScanMon.exe
pcscan.kr/down/Uninstall.exe
pcscan.kr/down/PCScanControl.dll

pcscan.kr/value.php?strMode=setup&strID=PCScan&arg=type1&strSite=&strPC=000c29ca888c&url=
pcscan.kr/settle.php?strID=PCScan&arg=type1&strPC=000c29ca888c&strSite=pcscan.kr
pcscan.kr/bill_danal/bill_home/with_bill.php?strID=PCScan&arg=type1&strPC=000c29ca888c&strSite=pcscan.kr
pcscan.kr/consultation.php


Countermeasure

Terminate the processes called PCScan.exe. You can use the ProcessExplorer to view and terminate processes.

Remove PCScan folder (which houses six files) located in C:\Program Files\pcscan\

Delete the system registry pcscan key from HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run, which refers to "C:\Program Files\pcscan\pcscan.exe". You can use the Autoruns to view and delete the key.

Delete the desktop shortcut.

Running updated antivirus

Related information

Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

8.21.2010

Litter Korean rogue lurking II

Se trata de otro rogue perteneciente a la camada que actualmente se encuentra al acecho. Su nombre es PC Boan Plus.
pcboanplus.com - 222.122.84.56 - KORNET KOREA TELECOM

Domains that resolve to the same IP:
postmaster.8282tv.co.kr
pspd.org

PcBoanPlus2SetupH.exe (0ab2cc07373a4b88a0084f12ae63f54f)



This rogue report a system of affiliates Pay-per-Install that resolves the domain to an IP address corresponding to the ISP "KRNIC".

211.33.123.40/pcboanplus/install.php?mac=000C29CA888C&partner=PcBoanPlus&ver=

file.pcboanPlus.com/app/updater/PcBoanPlus2Up.exe
file.pcboanplus.com/app/Client/PcBoanplus2.exe
pcboanplus.com/app/badinfo.php?Vn=2005010100&Kind=comp

s223.pc-korea.net/badlist/2010080700_badfile.dat



Countermeasure

Uninstall from Program Files
Running updated antivirus


Related information

Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!
Pirated Edition. Affiliate program Pay-per-Install
Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI 

Ver más

Litter Korean rogue lurking I

Language issues are not limited to developers of malicious code and the objectives of the criminals are far beyond any border, and although it is usually the largest flow of varieties are in English and, to a lesser extent Russian every now and then the guns are aimed at specific audiences, as in this case: Korean rogue.

MegaVaccine
megavaccine.com - 218.146.255.151 - KORNET KOREA TELECOM

The IP is also the following domains:
goodprivacy.co.kr
megavaccine.com
pc-privacy.co.kr
pc-up.co.kr
pcsweeper.co.kr
pctool.co.kr
privacyboan.com
privacyq.com
rprotect.co.kr
uprivacy.net
wowprotect.co.kr

megavaccine_setup.exe (2234041b04e072aa7585209fa66e8550)

down.megavaccine.com/autoupdate/MegaVaccine/MVaccine.exe
down.megavaccine.com/Update_db/addb.dat
down.megavaccine.com/Update_db/adsub.dat
down.megavaccine.com/Update_db/adtc.dat
down.megavaccine.com/Update_db/avmon.dat
down.megavaccine.com/Update_db/inter.dll
down.megavaccine.com/Update_db/pwdb.dat
down.megavaccine.com/Update_db/vsdb.dat
down.megavaccine.com/Update_info/2010081900-00-.txt
down.megavaccine.com/Update_ini/MegaVaccine/autoupdate.ini
down.megavaccine.com/app/weboard.html

Countermeasure

Uninstall from Program Files
Running updated antivirus


Related information
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más