Malware News Beware of Cancer trollware, might shut down your favorite AV, too

Der.Reisende

Level 45
Thread author
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,423
Security researcher MalwareHunter discovered today a new malware that he initially believed to be ransomware but ended up being just another annoying piece of junk that falls in the category of trollware, also known as crapware.

This piece of software, appropriately named "Cancer," doesn't destroy any files like ransomware, but merely makes your computer go bonkers by playing annoying music, blocking access to several applications, moving your windows and images across your screen, and popping up all sorts of windows out of nowhere.

This malware is what some security experts would call trollware, malware made with the sole purpose of annoying users and making their computer unusable.

Past examples include CainXPiiCleaner, discovered by GData malware analyst Karsten Hahn last November.

Read more @ the article source.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
The security goodguys too need some entertainment at work, don't they?
While some activities like windows-bombs can be really annoying and bit difficult to handle, this should not be something to worry about, unless one can not get access to process monitors or so.
I'd a scaled down experience of such windows bomb with a startup entry. Took some patience to kill it first, to remove it.
 
Last edited:

Like a Western!

Level 9
Verified
Well-known
Apr 6, 2016
440
its still a malware. do unwanted things/changes without our premission ! if your antivirus be really watching your system changes, should be able to stop this malware from do these troll things.. ! :D

i like to see how Kaspersky SystemWatcher will react to this trollware.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
i found the sample from hybrid-analysis, Dr.Web failed :D
i submit the sample for them, once they analys it , their behavior blocker should learn this behavioral algoritm, we'll see what happens :)
@Parsh as you have Kaspersky, may i ask you test the sample in your VM with Kasper ? :D
Good!
Kaspersky is on my main Host PC.
I'm currently testing malware with different setup in VM. Will let you know though :D
 

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
i found the sample from hybrid-analysis, Dr.Web failed :D
i submit the sample for them, once they analys it , their behavior blocker should learn this behavioral algoritm, we'll see what happens :)
@Parsh as you have Kaspersky, may i ask you test the sample in your VM with Kasper ? :D

Can you please upload it on zippyshare and post the link in the HUB for us to test it vs our AV?
thank you!;)
Malware Vault (Samples)
 

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
hmmm.... anyone has the sample?
Nice to test it =)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top