• Home
  • Et Cetera

Infosecurity.US

Microsoft Succesfully Cleanses 1 Million Systems

By Marc Handelman on December 1st, 2008

Recently surfaced reports detailing Microsoft Corporations‘ (NasdaqGS: MSFT) Malicious Software Removal Tool (MSRT) successful clearing of at least 1,000,000 infected computer systems have been posted at the  company’s Malware Protection Center Blog. The infections are of the Win32/FakeSecSen family of false anti-spyware software.

Distributed with the software giant’s latest Patch Tuesday Update (11/11/2008), the MSRT has, up to now, been a bit more low key, and rather unremarkable in it’s effectiveness…Read the full Microsoft statement on the effort after the break.

From the Microsoft Malware Protection Center Blog:

MSRT Review on Win32/FakeSecSen Rogues

Win32/FakeSecSen was added to MSRT November release as Hamish mentioned in his MMPC blog.  We’ve since observed MSRT removing FakeSecSen from 994,061 distinct machines.

Breakdown of these removals by regions is shown as below.

Region/Country

Distinct Machines Cleaned

United States

548,218

United Kingdom

74,343

France

47,581

Germany

43,347

Netherlands

28,724

Spain

23,027

Italy

18,453

Australia

16,287

Canada

16,180

Sweden

15,412

Other

162,489

There is no surprise about the prevalence of these rogues given our earlier telemetry analysis on other Microsoft AV products and tools. For comparison, the #1 family last month was Renos with 389,036 distinct machines cleaned in the first week and 655,535 machines for the whole month. And the most significant result for MSRT this year was the June release when we added eight game password stealer families, was Win32/Taterf with 1,246,792 machines cleaned by week 1 and 1,536,831 machines for the whole month.

One way to interpret this data is to look into the infection rate.  In the recent release of volume 5 of the Microsoft Security Intelligence Report we introduced “Computer Cleaned per thousand MSRT executions” (CCM).  During 1H08, the CCM for US for the full six months was 11.2. Within one week in November US CCM for all threats is 10.3 and US CCM for just FakeSecSen alone is 5.0. This reads: every one thousand machines in US scanned by MSRT during the last seven days, roughly five were infected with FakeSecSen rogues.

Normally each FakeSecSen installation contains one EXE, one or two DAT files, one Control Panel applet (CPL), one desktop shortcut and sometimes one uninstaller. It is interesting that only 20% of these removals contain executables of FakeSecSen. This indicates either the other 80% machines had at one point been infected by FakeSecSen and the threat was then manually and partially removed, or the machines were cleaned by other AV products/tools, or FakeSecSen had failed to install, etc. To put the number in perspective and adjust the FakeSecSen to count only the EXE, it is #2, behind Renos..

Threat Family

Distinct Machines Cleaned

Renos

565,728

FakeSecSen (EXEs)

198,812

Taterf

177,660

Zlob

175,559

Lolyda

118,130

Now how did one’s machine get infected by FakeSecSen? From our research a few Win32/Renos variants such as TrojanDownloader:Win32/Renos.Y, TrojanDownloader:Win32/Renos.AY, TrojanDownloader:Win32/Renos.EK are responsible for downloading FakeSecSen. The table below shows the top ten threats infecting machines that were also infected by FakeSecSen. Five of them are Renos.

Rank

Threat on FakeSec infected machine

Distinct Machines Cleaned

1

TrojanDownloader:Win32/Renos.AY

5,437

2

TrojanDownloader:Win32/Renos.Y

5,223

3

Trojan:Win32/Zlob.J

4,922

4

TrojanDropper:Win32/Zlob

3,076

5

TrojanDownloader:Win32/Renos

2,619

6

Trojan:Win32/Zlob.AU

2,040

7

TrojanDownloader:Win32/Zlob.AMV

1,627

8

TrojanDownloader:Win32/Zlob.gen!CJ

1,567

9

TrojanDownloader:Win32/Renos.AT

1,399

10

TrojanDownloader:Win32/Zlob.gen!AX

1,248

We suggest you get familiar with the behaviors of Win32/Renos especially the three variants mentioned above and be cautious out there with your web surfing and other internet usage.

The following table shows the top ten FakeSecSen EXEs.  We provide this data for any other antimalware vendors and security research firms who wish to solidify their detection capability or malware analysis.

Rank

FakeSecSen EXE

Distinct Machines Cleaned

1

0x594771CD995BA6A77DEB10BEAA27DFD30B4A6CF1

24,488

2

0xDCED8E211919CC57878B53C7E6D288A31DC1C6AB

8,696

3

0xA73CEE93F3EF7B913CDE29EB84DCBF43B41C4920

6,595

4

0x83B3ED7F420D6B06A0F7FA0D429E3B8098205446

6,482

5

0x8CE338D88245B7C5DB92BFB9C2FD3852039477D5

6,392

6

0x6F6BB37E574FC70FCD90B5075A9100D254C83286

6,035

7

0xDB3C727A2F99E04FA8595161A6ADD6889DD29320

5,949

8

0xD98221F3893C15DBAE130CB38F3A02856091E733

5,236

9

0x3FC84BC022F53B1BED34FFB59681CE2DD42F6AE2

5,225

10

0x0D4C8ECA468532A72C4840ACE58257A307CA06EA

4,821

MMPC is keeping an eye on this space and watching closely the activities of AV rogues and their evolution.  We strive for ensuring the safe Internet experience of our customers and we trust our colleagues in other industry leading firms are doing the same.

  • Microsoft Yanks Fake Security Software
  • Microsoft cleans fake antivirus tool from 994,061 PCs
Reblog this post [with Zemanta]

Categories: Data Security, Infosecurity
Tags: Anti Spyware, Anti-Virus, Fake Anti-Spyware Software, Features, Malware, Microsoft, MSRT, Software Patches

Related Headlines

    Related posts:

    1. Microsoft Windows Help Center Attacks Increase
    2. Microsoft Malicious Software Removal Tool Epic Fail
    3. Malware Author Toys With Microsoft Defender Group
    4. Microsoft Malicious Software Removal Tool Discovers Over 2 Million Infected PCs
    5. Latest Microsoft Attack Vector On Brink Of World Wide Exploitation

Comments are closed.

« Weekend Off! Sealand Based HavenCo Offline »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • XKCD: October Thirtieth
  • Weekend Off – Gone Fishing
  • ENISA Releases New Ad Hoc Working Group Report
  • Benson: The Torch Passeth
  • Happy Weekend!
  • FreeBSD Security Advisory – telnetd
  • Fourth Generation Mutant XSS Exploit Continues Twitter Attack
  • Bee
  • iPhone Firmware Updated, Addresses SMS Hack
  • Adobe Still Offering Insecure Reader Download
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe