[Symptom of Infection]
[Adware.Boanrnd.R] is installed by ActiveX without user agreement, and it induces users to automatic purchase for the fake Anti-Virus by showing infection warning.
- It adds itself to registry for automatic execution on system boot.
[PIC 1] Active X Installation Feature

[PIC 2] Scaning Feature

[PIC 3] Warning

[PIC 4] Require automatic purchase for fake Anti-Virus

[PIC 5] In case of cancel the purchase, showing the warning.

<Related URL>
hxxp://down.(...).com/BRNDinstRB_(...).exe hxxp://down.(...).com/update.php hxxp://down.(...).com/brndhk.dll hxxp://down.(...).com/brndupdater.exe hxxp://down.(...).com/brnduninst.exe hxxp://down.(...).com/brndpopd.dll hxxp://down.(...).com/brndwcher.exe hxxp://down.(...).com/(...).exe hxxp://(...).com/app_linkage/app_install.php?(...) hxxp://(...).com/app_linkage/app_setting.php?mac=(...) hxxp://www.(...).com/app_linkage/app_setting.php?mac=(...) hxxp://(...).com/app_linkage/app_install.php?addr=(...) hxxp://down.(...).com/update.php hxxp://(...).com/app_linkage/app_boot.php?ver=(...)
<File> [Adware.Boanrnd.R] creates files to below path.
(Desktop Folder)\º¸¾ÈRND.lnk
<Registry> [Adware.Boanrnd.R] creates registries to below path. HKLM\SOFTWARE\Classes\CLSID\{CF33A860-405D-4390-97B3-A77A308156C3} HKLM\SOFTWARE\Classes\Interface\{3B7CDD9F-5C42-423B-9ABF-20032B353657} HKLM\SOFTWARE\Classes\TypeLib\{634BFADD-CB3D-4AEE-8DF2-B087053014A3} HKLM\SOFTWARE\Classes\atxbrndgdp.atxbrndgd HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BOANrnd HKLM\SOFTWARE\boanrnd HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Name: boanrnd Value: "(Programs Folder)\boanrnd\boanrnd.exe"
<Folder> [Adware.Boanrnd.R] creates folders to below path.
(User Account Folder)\Startup\Programs\º¸¾ÈRND (Programs Folder)\Common Files\boanrnd (Programs Folder)\boanrnd
<Notation>
- "(All Users Account Folder)" could be different by user settings, and generally this is "C:\Documents and Settings\(All Users Account)". - "(Desktop Folder)"could be different by OS and generally this is "C:\Documents and Settings\(User Account)\Desktop". - "(Quick Launch Folder)" could be different by OS(or User), and generally this is "C:\Documents and Settings\(User Account)\Application Data\Microsoft\Internet Explorer\Quick Launch". - "(Temp Folder)" could be different by OS, and generally this is "C:\Documents and Settings\(User Account)\Local Settings\Temp". - "(Programs Folder)" could be different by OS and generally this is "C:\Program Files". - "(Windows Folder)" could be different by OS and generally this is "C:\Windows". - "(System Folder)" could be different by OS and generally this is "C:\Windows\System32"
|