Home > Insights > Blogs 

CA Community

This Blog

Warning: Dangerous Software – ‘Antivirus XP Pro’

Published: March 04 2009, 01:01 AM
by Zarestel Ferrer

This particular rogue software has been around since January 2009, and we’re currently seeing a significant number of downloader programs connected to this fake anti-virus. The image below shows what ‘Antivirus XP Pro’ looks like when it is installed on a system. Typical of a Win32/FakeAV trojan, it reports a number of fake threats detected on your system:

This Win32/FakeAV variant reports a number of fake threats detected on the system

It also modifies the desktop wallpaper to display the following image:

'AntivirusXP Pro' displays this warning message

which contains this message:

Warning
Dangerous Spyware

Many viruses were found on your computer such as : Trojan horse, PassCapture, etc
Your personal information can fall into in the “third hands”.
Please check up the computer with a special software.
Thank

Downloader families like Win32/Donloz, Win32/FakeAVDl and Win32/SillyDl are responsible for the distribution of these Win32/FakeAV variants. Variants of these families can install a couple of component files on the compromised system to scare the user into installing the fake security software. This malware also has some tricks and schemes to lure a user into downloading ‘Antivirus XP Pro’.

For example, when you use an affected system to browse to your favorite website, let’s say www.ca.com, you’ll get the web page below containing the message:

Too many errors and faults WERE found in your system. Possibly that IT WAS THE RESULT of virus attack.YOU MUST scan your system.

Example warning message displayed in the browser by 'AntivirusXP Pro'

You may also get the following scary warnings:

Warning! Your system is in danger. YOUR COMPUTER IS IN need OF full scanning.

Example warning message displayed in the browser by 'AntivirusXP Pro'

ERROR! Connection was RESET by remote server. This can be a reason for system faults, errors or critical data corruption. To prevent your critical data loss please do the full system scanning!

Example warning message displayed in the browser by 'AntivirusXP Pro'

All the messages point to a website hosting the Win32/FakeAV ‘Antivirus XP Pro’ variant.

Every time an affected system accesses a website, the component file "ntdll64.dll" (detected as a Win32/SillyBHO variant) contacts another website, which in this case is "onlinenotify.net", to retrieve the error messages to display at the top of every web page. Below you can see that the malware component file is a module of the web browser process being used, "firefox.exe".

Example of malware component acting as a module of the web browser

The capture below illustrates the sequence of HTTP access on an affected system. We can see that a call to "onlinenotify.net" is being made as we access the website.

Example of sequence of HTTP request 

A packet capture on this activity shows the source of the message inserted at the top of every web page – it is linked to the rogue ‘AntivirusXP Pro’ website.

Example of message in browser leading to the 'AntivirusXP Pro' website

Avoid this malware by only installing trusted software from trusted distributions. In addition, please keep your software patched and updated.

Happily for our customers, CA detects ‘AntivirusXP Pro’, and removes the files and registry keys associated with this rogue software.

Share this post:  EmailEmail

By: Zarestel Ferrer
Zarestel Ferrer is a Senior Research Engineer with CA's Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, he worked as a software developer and then moved into security as a Senior Anti-virus Engineer at Trend Micro. He also worked for PC Tools Research as a...
Read More..

9 people have left comments:

It is a shame that people fall for these viruses but I'm sure it can happen to anyone out there.

I mean c'mon - How many people actually fall for this seriously given the warning message?  

""Your personal information can fall into in the “third hands”.

Please check up the computer with a special software. ""

"Three hands" and "Check up their computer with a special software"?

Is there a category (age, geo, education) of home users who fall prey to these types of virusus?

Posted by: Grammer anyone? | March 5, 2009 10:32 AM

How do you get rid of it? This was helpful but it doesn't solve my problem.

Posted by: jess | March 9, 2009 4:22 AM

Most recent Norton antivirus 2k9 is usless at this time.

Posted by: Micah | March 15, 2009 12:25 AM

I was infected with this on Friday and I have no idea how. I am careful, work in IT and have a firewalled PC (F-Secure). But F-Secure support (no 1-800 number), told me  "Oh, we don't protect against that". Or against the 3-5 trojans I'm getting hit with on an almost daily basis for the last 2 weeks it seems. They had no answer for me.

malwarebytes removes this thing very effectively for free and when I heard that CA protects against it I decided to dump F-Secure and purchased CA's software this weekend.

Posted by: Andrea | March 16, 2009 8:15 AM

I got this through a Anime Manga website. Basically what happened was I went to the last page of the Manga and instead of showing a picture it infected my computer. So nobody has been able to figure out how to get rid of this besides CA. I'm asking because my computer is infected currently

Posted by: Jimb011 | March 18, 2009 7:49 PM

Use system restore, restore computer to previous date. go back into system restor uncheck drive button apply.  then re check system restore and apply

Posted by: Gary | March 21, 2009 8:20 AM

I was ambushed by the thing randomly.  I like to think I'm good about being safe.  I'm still unsure of how I managed to get it.  I'm trying to install malwarebytes but it's blocking installations.  Anyway to beat the trojan/virus so I can get rid of it?

Posted by: Desdinova | March 27, 2009 9:20 PM

How can I find the orignators of this software.

IF ANYONE KNOWS HOW TO TRACK THESE PEOPLE I WOULD LIKE TO HAVE PRIVATE CHAT. How about a wrongful damages class action lawsuit.

IS IT POSSIBLE TO LOCATE THE SERVER OR LOCATION?

Posted by: Ted | March 29, 2009 2:12 PM

How do I get rid of this virus? It has infected my PC and I dont know how.

Posted by: Me | April 30, 2009 11:18 AM

 
 
Page Tools