http://axvideodownload.com/ uses the same old fake "Video ActiveX Object Error" messages to lure viewers to download their fake plugin installer named setup_axplugin.exe.
At the time of this writing, the Ax Video Plugin was sparsely detected at VirusTotal, and only 4 AVs managed to detect it. Here's a report from VirusTotal scan:
AntiVir - TR/Crypt.XDR.Gen
AVG - BackDoor.RBot.EA
Panda - Suspicious file
Webwasher Gateway - Trojan.Crypt.XDR.GenWhen
setup_axplugin.exe is executed, it drops a bunch of malware files to %WINDIR% and creates few "Run" Registry keys to load these executables at system startup. These dropped files display fake security alerts, change Desktop wallpaper and try to download fake anti-spyware applications like SystemErrorFixer, SysCleaner and SpyBurner etc. This is how the Desktop looks after the infection!
0 comments:
Post a Comment