<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tekblog &#187; backdoor.bot</title>
	<atom:link href="http://tekblog.teksquisite.com/tag/backdoor-bot/feed/" rel="self" type="application/rss+xml" />
	<link>http://tekblog.teksquisite.com</link>
	<description>Tackling Technology One Byte At A Time!</description>
	<lastBuildDate>Thu, 09 Sep 2010 13:48:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>FacebookAgent is a Trojan Dropper</title>
		<link>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/</link>
		<comments>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 02:15:59 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[backdoor.bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebookagent]]></category>
		<category><![CDATA[green card]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1841</guid>
		<description><![CDATA[There has been chattering the past few days about unknown rogue software available for download on the Internet that lets you view private Facebook profiles. I can assure you that this new software called FacebookAgent is old news wagging a new wrapper. This is not just another scam! This rogue application also has a back [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F03%2Ffacebookagent-is-a-backdoor-bot-trojan-dropper%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F03%2Ffacebookagent-is-a-backdoor-bot-trojan-dropper%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>There has been chattering the past few days about unknown rogue software available for download on the Internet that lets you view private Facebook profiles.  I can assure you that this new software called <strong>FacebookAgent</strong> is old news wagging a new wrapper.  This is not just another scam!  This rogue application also has  a back door along with Trojans droppers put together by cyber-criminals to elicit financial information via social engineering techniques. Prior to examining FacebookAgent on a VM earlier today I ran Malwarebytes and had a clean scan with no infected files.  After installation of Facebook Agent and testing in a VM I ran Malwarebytes again and had 159 infected files!   (the results will be posted at the end of this article.) <strong>Domain:</strong> www.facebookagent[DOT]com  <strong>Current IP:</strong> 74.208.137.211 131 1&amp;1 Internet Inc<strong> PA</strong></p>
<p style="text-align: center;"><strong><img class="aligncenter size-full wp-image-1855" title="Shot6" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/Shot6.gif" alt="Shot6" width="519" height="419" /> </strong></p>
<p style="text-align: left;">Facebookagent.com website provides this Disclamer:</p>
<p style="text-align: left;"><em>&#8220;Facebook Agent is an automated help manual that guides you through the process of gaining a legal view of the desired profile. This process is completely legal and is achieved through the other party’s aproval and acknowledgement. This software and/or methods should not be used in any other case that is not mentioned above. All facebook trademarks are copyrighted to facebook.com. All actions taken through and in this application are on full responsibility of the user. Facebook Agent is in no condition responsible of any harm, damage or violations done while using this application. If at any stage of the process any party will find violation of law against them, the process should immidiately be terminated and reported to the administration team of the application. By clicking the Start button you agree to take full responsibility of the actions done by this application. All rights are copyrighted to facebook Agent 2009 &#8211; 2010. All trademarks found in this application belong to facebook Agent apart from facebook trademarks which are copyrighted to facebook.com. By clicking on the Start button you accept this terms and conditions.&#8221;</em></p>
<p style="text-align: left;">Most of the links at the <strong>FacebookAgent </strong>website result in saving or downloading <strong>setup.msi</strong>.  The msi installer loads Facebook Agent.exe and a database file in the Program Files directory.  The installer also loads Perflib_Perfdata640.dat into the local user profile temp directory and runs the database file under svchost.</p>
<p style="text-align: center;"><img class="size-full wp-image-1843 aligncenter" title="programfiles" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/programfiles.jpg" alt="programfiles" width="379" height="53" /></p>
<p style="text-align: center;"><img class="size-full wp-image-1844 aligncenter" title="files" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/files.jpg" alt="files" width="307" height="144" /></p>
<p style="text-align: left;">When you first run <strong>Facebook Agent </strong>there is no exit from the program.  Bad code and even worse downloads and toxic URLs await you. Since I did not choose to install the <strong>IWON toolbar</strong> featuring the <strong>MyWebSearch</strong> default search provider I had to participate in the Green Card Scam that is listed below.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1852" title="step-1-free-prize" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/step-1-free-prize.jpg" alt="step-1-free-prize" width="668" height="399" /></p>
<p style="text-align: left;"><span style="font-size: x-small;"><span style="font-size: small;">According to the flimsy interface above you have to click to claim what you have won!  Your prize is located at: </span></span>hXXp://html.usagc[DOT]org/step1landing_eng[DOT]html?afk=ranygnewcplcmp0309eng.  Then you have to fill out a form that includes your full name, email address, country of birth, marital status, and telephone number. You also have to answer this dropdown menu question:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1855" title="highschool" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/highschool.jpg" alt="highschool" width="261" height="49" /></p>
<p style="text-align: left;">After I filled out the online form with false information, I received this response:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1856" title="sue-dogears" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/sue-dogears.jpg" alt="sue-dogears" width="444" height="64" /></p>
<p style="text-align: left;">Canada, Mexico, and the United States are ineligible.  On the same page I was also given the option to select another country if I were a native of a qualifying country or if my parents were born in a qualifying country.  I opted for Australia and was quickly promoted to step 2 in the process!</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1858" title="prize" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/prize.jpg" alt="prize" width="526" height="385" /><img class="aligncenter size-full wp-image-1859" title="prize2" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/prize2.jpg" alt="prize2" width="498" height="370" /></p>
<p style="text-align: left;">I had a good smirk over the warning &#8220;using a stolen or fraud credit card number will automatically disqualify you from participating forever!!  USAGC will immediately cancel your application and pursue legal remedies.&#8221;</p>
<p style="text-align: left;"><strong>USAGC is a scam! </strong>Don&#8217;t fall victim to <strong>this Green Card  lottery scam!</strong> The <a title="green card" href="http://travel.state.gov/visa/immigrants/types/types_1322.html" target="_blank">DV-2011 Diversity Visa Lottery</a>( run by The U.S. Department of State)  online entry registration period ended on <strong>November 30, 2009</strong></p>
<p style="text-align: left;">I was soon bored with the Green card lottery scam so proceeded to install the <strong>IWON Toolbar</strong> and failed.   <img class="aligncenter size-full wp-image-1861" title="iwon" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/iwon.jpg" alt="iwon" width="583" height="307" /></p>
<p style="text-align: left;">After finishing the installation of IWON, I had to go to iwon.com to register for a free account.  Overall, you can only get to step 1 in Facebook Agent because you can&#8217;t get to step 2 without filling out credit card information.</p>
<p style="text-align: left;">Finally I ran Malwarebytes again to see what nasties Facebook Agent had installed.</p>
<div>Memory Processes Infected: 2</div>
<div>Memory Modules Infected: 1</div>
<div>
<div>Registry Keys Infected: 142</div>
<div>Registry Values Infected: 9</div>
<div>Registry Data Items Infected: 0</div>
<div>Folders Infected: 20</div>
<div>Files Infected: 86</div>
</div>
<div>
<div>Memory Processes Infected:</div>
<div>C:\Documents and Settings\test\Application Data\Microsoft\Network\svchost.exe (Trojan.Dropper) -&gt; Unloaded process successfully.</div>
<div>C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -&gt; Unloaded process successfully.</div>
<div>Memory Modules Infected:</div>
<div>C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -&gt; Delete on reboot.</div>
</div>
<div>Files Infected:</div>
<div>C:\Documents and Settings\test\Application Data\Microsoft\Network\wuauclt.exe (Backdoor.Bot) -&gt; Delete on reboot.</div>
<div>
<div>Registry Values Infected:</div>
<div>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft network service (Trojan.Dropper) -&gt; Delete on reboot.</div>
</div>
<div><strong>You can view the full Malwarebytes log <a title="here" href="http://docs.google.com/View?id=dch6xcnj_359jsthc8h" target="_blank">here</a>.</strong></div>
<div><strong> </strong></div>
<div>I did not have much time to pursue this today but have high hopes that other security experts will jump in and take a look at this backdoor!</div>
<div><strong>Until next time &#8212; Stay safe online!</strong></div>
<div><strong> </strong></div>
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=1841';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	<a href="http://www.websquisite.com/dezine.php"><span style="display: none;">Private</span></a></channel>
</rss>
