Recently, a weather app caught our attention by doing something far worse than predicting rain all the time. It installed all the ingredients for a false Blue Screen Of Death (BSOD) with a number to call for assistance.
As the app is bearing the same name as one comic book “super villain” this might have been a warning that there was something up with this one. But offered in a bundle you come across the most useless of apps, as we have told our regular readers many times. So why not a weather app. The app itself does not do much more than give you the weather in a certain US zip code. You type in the ZIP code and it will tell you what you are missing.
But what it does in the background is more worthy of the super villain reference. A bat file call sc.bat sets two Scheduled Tasks to work.
So you will understand that I just had to trigger them to find out what they do. SysInfo.exe was unresponsive on my system, but amdave64Win.exe certainly did not disappoint me as it opened a series of command prompts and did a grand finale ending at this:
Although we have seen many examples of scare tactics using BSOD screens, , , , , using a seemingly harmless weather app and then wait for a considerable period of time is a bold new tactic we haven’t seen before.
Detection and protection
Malwarebytes Anti-Malware detects WeatherWizard as PUP.Optional.WeatherWizard and the components of the Tech Support Scam as Rogue.TechSupportScam. A removal guide with more details can be found at our forums.
We looked at a simple weather app that turned out to have a twist and install a fake BSOD inviting users to call a Tech Support Scam number.