Page 4 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Jan 28, 2012 6:42 pm
by rkhunter
markusg wrote:FakeSysdef (systemcheck):
mCl7w2YFKX8LGN.exe
MD5: f1ab6c2ab5fd 6d229e43f2f22911aa9f
McAfee -> Artemis!F1AB6C2AB5FD

BitDefender, F-Secure, GData -> Kazy.53751

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 30, 2012 8:51 am
by rkhunter
Security Shield

MD5: 5ceb2508203bbf7bc25c2497cb48284f
2/43

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Feb 02, 2012 10:40 am
by ISergey256
Security Shield
MD5: 8C9FE5233C0782C71C8DA613147562FE

4 / 43

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Feb 03, 2012 9:26 am
by ISergey256
Smart Anti-Malware Protection 19 / 43
Home Security Solutions 19 / 43

Original and VirtualBox Fixed.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Feb 04, 2012 9:29 am
by Cody Johnston
Internet Security

MD5: 5c2009fef7b1eae1d292299772da156a

VT: https://www.virustotal.com/file/42fa715 ... 328347536/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Feb 04, 2012 6:19 pm
by Xylitol
FakeAV Landing package

Landing package, included some specials, like the SWF landing page.

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Feb 05, 2012 6:21 pm
by Xylitol
Smart Protection 2012 + Payment processing

Image

Image

Original: 2/42
https://www.virustotal.com/file/f515548 ... /analysis/

Unpack: 4/43
https://www.virustotal.com/file/37a0cea ... /analysis/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Feb 06, 2012 8:54 am
by rkhunter
4 Winwebsec - Security Shield

30931c85b1c86e2a3a62f05fecd0d88a
575E3F69C90C3AAC80B7105FBA5EE6B3
BB44C55F3F209FE249AA39A09F79755D
C8208F6C05D4276CA52AD3EFAD1366B1

FakeRean - SecurityMonitor

aaa6ce5c677b3c38cfb9f6d4e2d9f878

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Feb 06, 2012 4:01 pm
by Xylitol

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Feb 07, 2012 12:23 pm
by rkhunter
FakeSysdef

MD5: d1d0dc875b81bd1eb5404286104c00e6
13/43

FakeRean - Security Monitor

MD5: 7daa49fa0642ad007413cff953c1a8e0
16/41

Winwebsec - Security Shield

MD5: 3e9a80bc1b6ac9896767fe8840a8cbb1
MD5: 72672ecc501cfa83f2c662d12020b41c