Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    November 2014
    S M T W T F S
    « Oct    
     1
    2345678
    9101112131415
    16171819202122
    23242526272829
    30  
  • About Us

    Trend Micro recently discovered malware posing as the Trend Micro iClean tool being sent through email by Chinese hackers. This is a screenshot of the email message:


    Figure 1. Spam email in Chinese looking very much like it came from Trend Micro.

    The email message was fashioned to look like an email message sent by Trend Micro, with the file attachment iClean20.EXE.

    But be warned: iClean20.EXE is detected by Trend Micro as TROJ_FAKECLEAN.A. TROJ_FAKECLEAN.A drops two files, one detected as BKDR_POISON.GO and the other, the real iClean tool. Dropping the legitimate tool along with the malware must have been done to fool users that the message was indeed from Trend Micro, and that the tool was the only file downloaded into their systems.

    BKDR_POISON.GO opens a random port and allows a remote user to execute commands on the affected system.

    The Trend Micro iClean tool is an application that combines Rootkit Buster and SICTool. Its main functions include:

    • Remove common viruses and Rootkit program
    • IE cache folder clean-up
    • Temp folder clean-up system
    • Collection trend antivirus software virus logs
    • Collection of diagnostic information related to malicious code

    The real Trend Micro iClean tool is available for download at the Trend Micro Taiwan site:


    Figure 2. The real Trend Micro iClean tool at the Trend Micro Taiwan site.

    Trend Micro will NEVER send tools or applications through email. Trend Micro advises users to be wary in opening and downloading attachments from unknown users and to download tools or applications from trusted sites only.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon






     

    © Copyright 2013 Trend Micro Inc. All rights reserved. Legal Notice