Page 41 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 05, 2012 10:10 am
by dumb110
Live Security Platinum.

When u select it you get to see a new icon. ;)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 19, 2012 8:17 am
by Blaze
Live Security Platinum

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Sep 22, 2012 2:19 am
by EP_X0FF
System Progressive Protection

VirusTotal
https://www.virustotal.com/file/626e918 ... /analysis/

Main window with embedded detections.

Image

Security status.

Image

Purchase form.

Image

Uses usual autorun reg entry. Terminates running GUI programs with fake alert messages. Another reincarnation of the Security Shield. Thanks for sample to markusg.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Sep 22, 2012 6:55 am
by Win32:Virut
Thanks

One more sample:

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Sep 25, 2012 6:00 pm
by markusg

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Sep 30, 2012 5:36 pm
by rough_spear
Hi All, :D

Windows Security 2012

With Necurs Rootkit.

Web Links -
hxxp://scan-av-fis.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO11QWjkoL4jZPxOUaKMDkhQ==

hxxp://winsecsys6.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO1wcUi0le4mQcw lMfsTkhQ==

hxxp://great-antispy2012.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO11oT30sOsTccyupJI5PkhQ==

Above url carry same file.
Attached file includes rootkit driver and dropper and sandboxie BSA reports.

Regards,

rough_spear. ;)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Sep 30, 2012 6:53 pm
by gied
Do the rogue produces visible screen for anyone? Or is it VM-protected?
rough_spear wrote:Hi All, :D

Windows Security 2012

With Necurs Rootkit.

Web Links -
hxxp://scan-av-fis.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO11QWjkoL4jZPxOUaKMDkhQ==

hxxp://winsecsys6.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO1wcUi0le4mQcw lMfsTkhQ==

hxxp://great-antispy2012.com/?c=RaEMLDkYzTQrhIQYxO3aByW/zb7zW2GSiNy 2HVZf8nAl VQznWWinHO11oT30sOsTccyupJI5PkhQ==

Above url carry same file.
Attached file includes rootkit driver and dropper and sandboxie BSA reports.

Regards,

rough_spear. ;)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Oct 01, 2012 7:17 am
by Cody Johnston
XP Defender 2013

Image

Low detection on VT: 2/42

https://www.virustotal.com/file/910e1f4 ... /analysis/

MD5: d016624eda407bce8982b029631e7ec8

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Oct 01, 2012 3:28 pm
by Win32:Virut
Key:
Code: Select all
3425-814615-3990

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Oct 01, 2012 5:12 pm
by frame4-mdpro
Win32:Virut wrote:Key:
Code: Select all
3425-814615-3990
Is this for the XP Defender 2013 ?