Home Malware Programs Rogue Anti-Spyware Programs BoanSupport

BoanSupport

Posted: April 7, 2011

BoanSupport is a recent Korean rogue security program that shows fake infected system scan results and inaccurate system warnings to imitate useful functions. BoanSupport offers this erroneous information to trick you into registering BoanSupport for money, enabling fraudulent charges on your credit card. Removing BoanSupport from your PC is highly recommended, since BoanSupport may endanger the computer by changing system settings, hijacking your web browser or blocking downloads or applications.

BoanSupport is an Easily-Caught Intruder

BoanSupport is simple enough to recognize, since all of BoanSupport's text and the program name itself are presented in Korean. As a rogue security program, BoanSupport is likely to add Registry entries that let BoanSupport run automatically whenever Windows boots. Besides the program itself, you may also see a BoanSupport icon on your desktop and a BoanSupport shortcut added to your toolbar.

BoanSupport may display some or all of the following harmful behaviors, but isn't limited to them:

  • Security programs may be blocked, with or without accompanying error messages. BoanSupport uses these messages as a front – your programs aren't infected or otherwise damaged; BoanSupport simply doesn't want you to run any software that could delete BoanSupport!
  • Your web browser may behave oddly, showing error messages and alerts for ordinary websites, redirecting you to unusual websites or changing your homepage or search results. These are signs of BoanSupport making browser hijack attacks. Exposure to malicious sites through hijacking is a common way to acquire other malware infections and lose sensitive information to fraudulent websites.
  • Downloads may be canceled or interrupted. BoanSupport may do this to stop you from downloading anti-malware applications. In many instances, this simple attack can be thwarted by renaming the file before downloading it.
  • A wide range of different fake alerts and system scans are used to incite panic. Ignore all attempts by BoanSupport to get you to register the rogue security program, since registering BoanSupport will only put your credit card in danger of repeated fraudulent charges. Speak with your credit card company and have any charges revoked if you've already purchased a registration key for BoanSupport.

Where You Can Find BoanSupport Without Meaning To

Typical infection methods for BoanSupport and similar rogue security programs include:

  • Being installed by other PC threats such as Trojans. Trojans will often infect a system as part of a download from an insecure source like a P2P network, or by being embedded in malicious scripts in advertisements or hostile websites.
  • Being installed through fake online scanners. These scanner applications will pretend to find infections on your computer that BoanSupport or another rogue security program can remove. Since the infection display is just as fake as BoanSupport's positive features, you have nothing to gain from taking the scanner at BoanSupport's word.
  • Being deliberately installed through a website that promotes BoanSupport and other rogue security products. These websites will look very similar to real security software sites, and can easily trick users into believing that BoanSupport is a helpful application. Currently the only known website that promotes BoanSupport is boansupport.co.kr, but most rogue security programs have multiple websites for promotion. Be particularly cautious around websites with the .kr suffix, as this indicates a Korean website and BoanSupport is, of course, Korean malware.

If you find yourself in need of deleting BoanSupport, you should turn to well-known and up to date anti-malware software. Deleting BoanSupport's files one by one without software-based help is more likely to cause system errors than simply removing BoanSupport with a tool designed for it.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\documents and settings\{username}\Desktop\boansupport_setup.exe
    2 c:\program files\boansupport
    3 c:\program files\boansupport\boansupport.exe
    4 c:\program files\boansupport\boansupportcfg.exe
    5 c:\program files\boansupport\boansupportmon.exe
    6 c:\program files\boansupport\uninst.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\BoanSupportHKEY_LOCAL_MACHINE\SOFTWARE\BoanSupportPartnerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BoanSupport.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BoanSupportHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BoanSupport

One Comment

Loading...