Page 16 of 34

Milestone Antivirus

PostPosted:Wed Jun 08, 2011 6:58 am
by Xylitol
Milestone Antivirus

Image

20/42 >> 47.6%
http://www.virustotal.com/file-scan/rep ... 1307516228

for spoof a referrer if you have firefox: download refspoof here ~ https://addons.mozilla.org/en-us/firefo ... /refspoof/ or RefControl: https://addons.mozilla.org/en-us/firefo ... efcontrol/
In case of refspoof, for make it work with firefox 4.* download the .xpi and rename it to .xpi.rar
Extract the install.rdf, open it with notepad and change the line
Code: Select all
<em:maxVersion>3.0.*</em:maxVersion>
by
Code: Select all
<em:maxVersion>4.*.*</em:maxVersion>
After, just repack the file and install.

print.graphytop.be/SpryAssets/wp-page.php?k=Olympic-Stadium-Design
redirect me on: hxxp://ziqlrrin.co.cc/?s=sF02x5vHzDPss90cW%2BxIuTF6DEG3BXiqO8QeR%2BBqhq4ii28rS%2Fbop8pxMGQ5VwgEhA%3D%3D

Image

Abuse sent ~ http://www.co.cc/prosecution/prosecution.php
I've ripped the html page of the fake scanner if you guys are interested, btw most interesting fake scanner page i've see for the moment are the security shield one, they use base64 then rsa with a 26 or 27 bits modulo and then again base64, and this just with javascript :D
heavy to load but fun to 'depack'

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Jun 08, 2011 7:54 am
by EP_X0FF
Xylitol wrote:print.graphytop.be/SpryAssets/wp-page.php?k=Olympic-Stadium-Design
redirect me on: hxxp://ziqlrrin.co.cc/?s=sF02x5vHzDPss90cW%2BxIuTF6DEG3BXiqO8QeR%2BBqhq4ii28rS%2Fbop8pxMGQ5VwgEhA%3D%3D
Yes me too. Drops this one (0 at VT), crypted and then packed by UPX. Ms Removal Tool from (c) NecroSoft, lol

http://www.virustotal.com/file-scan/rep ... 1307519223

Windows Troubles Killer

PostPosted:Wed Jun 08, 2011 8:53 am
by ngyikp
Windows Troubles Killer

What's next? Windows Problem Assassination?

Image

Windows Monitoring Utility

PostPosted:Wed Jun 08, 2011 9:33 am
by bitx
Windows Monitoring Utility

But Windows Problem Assassination sounds fair enough to me, ngyikp :)

Image

Re: Windows Monitoring Utility

PostPosted:Wed Jun 08, 2011 9:35 am
by Xylitol
Windows Monitoring Utility (another sample)

Image

9/42 >> 21.4%
http://www.virustotal.com/file-scan/rep ... 1307525147
Fake scanner: hxxp://defender-ptwvd.in/e19b21b55a730253/sa1/0/
hxxp://freetrialmail.com/red0.php
edit: ah, bitx was more fast than me

Security Essentials Ultimate Pack

PostPosted:Wed Jun 08, 2011 6:56 pm
by Xylitol
Security Essentials Ultimate Pack

Image

They have forget to remove old strings
Image

26/43 >> 60.5%
https://www.virustotal.com/file-scan/re ... 1307325871

----

Image

22/43 >> 51.2%
http://www.virustotal.com/file-scan/rep ... 1307560777

Security Central

PostPosted:Thu Jun 09, 2011 2:22 pm
by bitx
Security Central

Image

Rogue:Win32/FakePAV

PostPosted:Thu Jun 09, 2011 3:54 pm
by markusg

Windows Work Checker

PostPosted:Thu Jun 09, 2011 4:09 pm
by bitx
Windows Work Checker

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Jun 09, 2011 4:10 pm
by EP_X0FF
@bitx

from day to day names become more and more idiotic, don't you think so? :)