Page 43 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Oct 30, 2012 8:26 am
by maddy
Hi,

here sample for Windows Custom Safety

- maddy

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Nov 02, 2012 10:45 am
by devstaff
Just me thats gets tired on Fake.Vimes fakeavs? Because there is so many versions of them:/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Nov 02, 2012 1:58 pm
by EP_X0FF
devstaff wrote:Just me thats gets tired on Fake.Vimes fakeavs? Because there is so many versions of them:/
It because they all basically the same. Only redesigned GUI and randomized names. I remember 3 year ago I could go on MDL and download bunch of FakeAV's and most of them were totally different - different design (not only GUI), different distribution group etc. All ended in 2010. Now boring crap mostly from Severa and ko.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Nov 02, 2012 9:59 pm
by Xylitol
EP_X0FF wrote:Now boring crap mostly from Severa and ko.
Severa isn't in spam/pharma business ?

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Nov 03, 2012 3:18 am
by EP_X0FF
Xylitol wrote:
EP_X0FF wrote:Now boring crap mostly from Severa and ko.
Severa isn't in spam/pharma business ?
Security Shield type FakeAV associates for me only with this guy as it initial promoter. Dont really know if he still promotes it distribution directly like before. But yes you right, last time I saw it was speaking about spam services based on his own mailer :)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Nov 03, 2012 10:01 pm
by Malwarehunter
Image
Kaspersky Internet Security 2013

tre.exe - Trojan.Win32.FakeAV.oddg

New malicious software was found in this file. It's
detection will be included in the next update. Thank you for your help.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Nov 04, 2012 4:54 am
by Cody Johnston
XP/Vista/Win 7 Antivirus Pro 2013

Image

VT 11/42:
https://www.virustotal.com/file/6b81b3a ... /analysis/

Puts file association in HKCU\Software\Classes\.exe to start itself

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Nov 04, 2012 8:48 pm
by Win32:Virut
Hello,

XP/Vista/Win 7 Antispyware Pro 2013

File attached.

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Nov 04, 2012 10:36 pm
by gied
Win32:Virut wrote:Hello,

XP/Vista/Win 7 Antispyware Pro 2013
It launches antivirus Pro 2013 version for me, not antispyware ?

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Nov 04, 2012 10:47 pm
by Cody Johnston
gied wrote:
Win32:Virut wrote:Hello,

XP/Vista/Win 7 Antispyware Pro 2013
It launches antivirus Pro 2013 version for me, not antispyware ?
This one has random names. Sometimes may be slightly different than what was originally posted. Still same infection though.