Peaches Posted October 24, 2009 Report Share Posted October 24, 2009 Oct23, 2009FAKEAV Goes Open Source… Or Not?by David Sancho (Malware Researcher) In the recent FAKEAV spam campaign, I realized something was off. Once the user clicks the URL and gets the bogus Antivirus 2010 up and running on the system, additional files are added. The files I found added are related to ClamAV, the open source AV toolkit for UNIX. The files include the ClamAV virus definition file and some newly-downloaded DLLs such as htmlayout.dll and pThreadVC2.dll. These files (DLLs and ClamAV definition file) are needed to run the open source antivirus software. So why are legitimate AV-related files included in the routines of a FAKEAV malware? Details & screenshots – TrendLabs - http://blog.trendmicro.com/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.