Page 2 of 6

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Mon Jan 13, 2014 5:32 pm
by Win32:Virut
Windows Prime Booster

Image

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Tue Jan 14, 2014 12:21 pm
by hx1997
Smart Guard Protection - Malware Security Suite

looooool
捕获3.png
捕获3.png (86.77 KiB) Viewed 887 times

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Wed Jan 15, 2014 6:57 pm
by Win32:Virut
Windows Prime Shield

Image

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Fri Jan 17, 2014 10:28 am
by hx1997
Windows Prime Shield

VT 1 / 47
https://www.virustotal.com/en/file/9275 ... 389954409/
捕获3.png
捕获3.png (87.61 KiB) Viewed 807 times

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Sun Jan 19, 2014 10:58 am
by Win32:Virut
Code: Select all
hxxp://zhnskks.servehttp.com/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvJheVQzm+YhzfWz1MPnw1S6zBdyf5Nf5Siz6QlCgCm4K+ByoM=
Empty file for me :(

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Mon Jan 20, 2014 4:52 pm
by Win32:Virut
Image

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Sat Feb 01, 2014 6:21 pm
by dairu87
Found this on a customer's machine today. Same old variant still using svc-Random.exe. they are really changing the name on these guys a lot this time around :P

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Sun Feb 02, 2014 2:50 am
by Windows

Windows Antivirus Master

PostPosted:Sun Feb 09, 2014 11:05 pm
by dairu87
Another one of the Windows FakeAV, still using the same components... just changing up the name. Looks like a lot of this is coming from those fake Microsoft Security Essentials pop-ups, at least for the people I have talked to.

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Mon Feb 10, 2014 11:06 pm
by dairu87