Page 2 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Jan 14, 2012 1:56 am
by Xylitol

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Jan 14, 2012 10:43 pm
by Xylitol
due to requests, i've fixed Internet Security Guard, this sample should run on vmware without auto-destruction and shit's

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Jan 17, 2012 7:50 am
by rkhunter
FakeRean - XP Home Security 2012

MD5: dd7b17ea3f35f0f52da10794031dd5b2

1/43

Code 9443-077673-5028 from http://www.kernelmode.info/forum/viewto ... 390#p11027 works fine.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Jan 19, 2012 9:22 am
by Ramtadryla
Just came across Security Monitor 2012 fake AV. Seems to be a new version. The registration code LIC2-00A6-234C-B6A9-38F8-F6E2-0838-F084-E235-6051-18B3 no longer works...

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Jan 19, 2012 4:08 pm
by Neurofunk
FakeSysDef with low Detection:
https://www.virustotal.com/file/e39aac7 ... /analysis/

Found it along side TrojanDownloader:Win32/Karagany.I with PWS:Win32/Fareit.A on a machine

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Jan 22, 2012 8:10 pm
by Xylitol
AV Protection Online
Code: Select all
http://core6575.opensourceavpro.com/setup.exe

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 23, 2012 9:03 am
by Ramtadryla
A sample of Smart Protection 2012 fake AV.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 23, 2012 9:53 am
by Xylitol
AntiVirus
it's old, but seriously.. best GUI ever :lol:

Image

https://www.virustotal.com/file/cfd1d09 ... /analysis/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 23, 2012 12:55 pm
by bitx
Internet Security 2012

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 23, 2012 1:49 pm
by rkhunter
bitx wrote:Internet Security 2012
Enter valid email please!
To continue please restart the program. Press OK to close the program.
Wrong activation code!
Wrong activation code! Please check and retry

has detected a leak of your files though the Internet.
We strongly recommend that you block the attack immediately

items are critical privacy compromising content
items is medium privacy threats
items are junk content of low privacy threats

has detected that a new Threat Database is available.

All threats has been succesfully removed.

Attention! We strongly recommend that you activate
for the safety and faster running of your PC.

Security Warning!
Malicious program has been detected.
Click here to protect your computer.

File
is infected by W32/Blaster.worm
Please activate
to protect your computer.