Page 2 of 46
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sat Jan 14, 2012 1:56 am
by Xylitol
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sat Jan 14, 2012 10:43 pm
by Xylitol
due to requests, i've fixed Internet Security Guard, this sample should run on vmware without auto-destruction and shit's
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Tue Jan 17, 2012 7:50 am
by rkhunter
FakeRean - XP Home Security 2012
MD5: dd7b17ea3f35f0f52da10794031dd5b2
1/43
Code
9443-077673-5028 from
http://www.kernelmode.info/forum/viewto ... 390#p11027 works fine.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Jan 19, 2012 9:22 am
by Ramtadryla
Just came across Security Monitor 2012 fake AV. Seems to be a new version. The registration code LIC2-00A6-234C-B6A9-38F8-F6E2-0838-F084-E235-6051-18B3 no longer works...
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Jan 19, 2012 4:08 pm
by Neurofunk
FakeSysDef with low Detection:
https://www.virustotal.com/file/e39aac7 ... /analysis/
Found it along side TrojanDownloader:Win32/Karagany.I with PWS:Win32/Fareit.A on a machine
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sun Jan 22, 2012 8:10 pm
by Xylitol
AV Protection Online
Code: Select allhttp://core6575.opensourceavpro.com/setup.exe
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Mon Jan 23, 2012 9:03 am
by Ramtadryla
A sample of Smart Protection 2012 fake AV.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Mon Jan 23, 2012 9:53 am
by Xylitol
AntiVirus
it's old, but seriously.. best GUI ever :lol:
https://www.virustotal.com/file/cfd1d09 ... /analysis/
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Mon Jan 23, 2012 12:55 pm
by bitx
Internet Security 2012
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Mon Jan 23, 2012 1:49 pm
by rkhunter
bitx wrote:Internet Security 2012
Enter valid email please!
To continue please restart the program. Press OK to close the program.
Wrong activation code!
Wrong activation code! Please check and retry
has detected a leak of your files though the Internet.
We strongly recommend that you block the attack immediately
items are critical privacy compromising content
items is medium privacy threats
items are junk content of low privacy threats
has detected that a new Threat Database is available.
All threats has been succesfully removed.
Attention! We strongly recommend that you activate
for the safety and faster running of your PC.
Security Warning!
Malicious program has been detected.
Click here to protect your computer.
File
is infected by W32/Blaster.worm
Please activate
to protect your computer.