Page 24 of 34

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 21, 2011 8:28 pm
by Xylitol
EP_X0FF wrote:
rough_spear wrote:Hi, ;)
One more Fake AV.
This is Total Protect FakeAV written on dot net.

It is aggressive - terminating starting application with fake virus warning alerts - usual behavior for this type of FakeAV.

Runs from X:\Documents and Settings\UserName\Application Data\

via

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Exposed here: http://xylibox.blogspot.com/2011/09/tra ... total.html

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Sep 22, 2011 3:22 pm
by CodeAddiction
Is there a serial number for this one?

Re: Malware Requests

PostPosted:Fri Sep 23, 2011 3:59 am
by hnpl2011
I'm looking for samples of the fakeAV (security shield) was hack bittorent website.( 2011/09/14)
follow sophos then the virus name: CXmal/FakeAV-A.
more info:
http://blog.bittorrent.com/2011/09/13/s ... -incident/
http://nakedsecurity.sophos.com/2011/09 ... d-for-p2p/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Sep 23, 2011 8:26 am
by EP_X0FF
BTW regarding to previously posted by rough_spear sample. It's actually multiple dropper with 6 different malwares inside.

Alureon.DX (TDL4)
Cycbot.B (GBot)
Harnig.S (AdvLoad)
TotalProtect
Personal Shield downloader
Hosts trojan

Re: Malware Requests

PostPosted:Fri Sep 23, 2011 8:36 am
by bitx
hnpl2011 wrote:I'm looking for samples of the fakeAV (security shield) was hack bittorent website.( 2011/09/14)
follow sophos then the virus name: CXmal/FakeAV-A.
more info:
http://blog.bittorrent.com/2011/09/13/s ... -incident/
http://nakedsecurity.sophos.com/2011/09 ... d-for-p2p/
File attached :)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Sep 23, 2011 2:35 pm
by CodeAddiction
Xylitol said:
"There is no serial form, for this fakeAV."
Thanks.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Sep 27, 2011 10:19 pm
by Xylitol
Striker wrote:Target: about.exe

VT: http://www.virustotal.com/file-scan/rep ... 1317157615
Yamba affil related exe
more infs ~ http://xylibox.blogspot.com/2011/09/tra ... twork.html

Advanced PC Shield 2012

PostPosted:Thu Sep 29, 2011 9:29 pm
by Xylitol
Advanced PC Shield 2012

http://www.virustotal.com/file-scan/rep ... 1317324474

Image

Image
s/n: 8945315-6548431

29b9a.sys
Image

Security Sphere 2012
http://www.virustotal.com/file-scan/rep ... 1317326682

Image

Image
s/n: 8945315-6548431

Privacyn

PostPosted:Thu Sep 29, 2011 11:49 pm
by Striker
Privacyn

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Sep 30, 2011 8:45 am
by EP_X0FF
More Security Sphere 2012 samples, VT 2/ 43 (4.7%)

66 files, multipart archive

pass: malware