Categorized | AVG

Virus uses Antivirus?

Usually, if we talk about virus and antivirus, it is more or less connected with detections. So if I say a malware uses antivirus to do bad things, will that be interesting?

Recently, AVG caught a kind of StartPage malware which uses Kingsoft WebShield as part of itself to achieve its aim.

Kingsoft is one of the most popular antivirus companies in China. Its web shield is desgined to protect users from phishing and injected websites to surf on line safely. It has two well known functions, locking IE’s homepage and page redirection, which are just what the malware take advantage of.

This malware combines modules from Kingsoft:

Image1

It would be clearer if we have a look at the digital signatures:

Image2

And modified configuration files:

Image3

Where kws.ini contains homepage settings, of course filled with faked URLs as you can see in this detail:

Image4
And Spitesp.dat which contains the list of URLs that is used for homepage redirection. That means, if you try to access these URLs, you will be redirected to the homepage or a certain URL prior configured:

Image5

Just take a look at these URLs. We can see that some of the popular internet websites are also included.

So how does this malware uses Kingsoft WebShield to do bad things?

Actually, this malware is packed in NSIS package (Nullsoft Install System). Below is script decompiled from the package by AVG engine.

Image6
First of all, we can see that this malware will search the process named ‘KSWebShield.exe’ which means the Kingsoft WebShield is already running. If it finds out, it will stop and remove the Kingsoft WebShield service.

Second, the malware will drop the needed Kingsoft WebShield modules into directory below:

Image7

Third, it will drop the configuration files, mentioned previously, into folder from which Kingsoft WedShield will read the settings by default:

Image8

At last, this malware will run a batch file to install and run the Kingsoft Web Shield service:

Image9

So far, the Kingsoft WebShield which has been configured malicious took effect. That means, your browsers’ homepages are faked and you will be redirected to the faked homepage if you try to access the URLs listed in the configuration file.

Image10
Kingsoft WebShield is a powerful browser protector. Maybe because of its power, it attracts malwares’ interest. Unluckily, malwares can just change the configuration files to take advantage of this power to do bad things. Is this a warning to others?

Jason Zhou & Hynek Blinka

 

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago