Page 11 of 46
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Mar 29, 2012 7:35 am
by erikloman
Looking for dropper of "Windows No-Risk Agent". Thanks!
EDIT: Never mind, its the same as "Windows Problems Stopper" and several others.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Mar 29, 2012 10:20 am
by rough_spear
Hi All, :D
Here is Windows Software Saver.
File - setup.exe
weblink -
hxxp://centerscannerprocesses.info/bb61f9bcec711d56/6/
hxxp://durhampowerequipment.com/mailer/examples/av6.php
VT link -
https://www.virustotal.com/file/945be94 ... /analysis/
File - Protector-mfhh.exe
VT link -
https://www.virustotal.com/file/2c0f5ee ... /analysis/
Regards,
rough_spear. ;)
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Mar 29, 2012 10:41 am
by rough_spear
Hi All, :D
Windows Managing System. :evil:
Files - setup.exe ---> dropper.
web link - hxxp://cleanavcenter.info/bb61f9bcec711d56/6/setup.exe
VT link -
https://www.virustotal.com/file/942a388 ... 333016871/
MD5 - 7dffd5694a23451c9acd831f4e458b2b
File - Protector-xxxx.exe (xxxx= some random characters) ----> dropped.
VT link -
https://www.virustotal.com/file/065424a ... 333017057/
MD5 - 37f5df628ae15d07f8d5a1198043acb3
Regards,
rough_spear. ;)
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 8:12 am
by thisisu
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 8:32 am
by rkhunter
One more "Windows Managing System" - FakePAV.
MD5: 615313C1ED7C4AD298AC361EC1534933
2/42
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 12:56 pm
by thisisu
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 1:42 pm
by thisisu
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 2:18 pm
by EP_X0FF
Rogue Winwebsec (alias Security Shield and other non meaninful names). Comes from very lazy guys (firstly this pack was discovered about 1 year ago) that have outdated BH software and old malware packs along with fresh recrypted samples. 79 samples in multipart RAR archive, pass "infected" without quotes.
Typical current detection according to VT
9 / 42
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Mar 30, 2012 10:23 pm
by thisisu
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sat Mar 31, 2012 3:29 am
by EP_X0FF
Fresh with low detection ratio. Pass "infected" without quotes.
https://www.virustotal.com/file/23fc540 ... 333164424/