Page 24 of 34
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Wed Sep 21, 2011 8:28 pm
by Xylitol
EP_X0FF wrote:rough_spear wrote:Hi, ;)
One more Fake AV.
This is Total Protect FakeAV written on dot net.
It is aggressive - terminating starting application with fake virus warning alerts - usual behavior for this type of FakeAV.
Runs from X:\Documents and Settings\UserName\Application Data\
via
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Exposed here:
http://xylibox.blogspot.com/2011/09/tra ... total.html
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Sep 22, 2011 3:22 pm
by CodeAddiction
Is there a serial number for this one?
Re: Malware Requests
PostPosted:Fri Sep 23, 2011 3:59 am
by hnpl2011
I'm looking for samples of the fakeAV (security shield) was hack bittorent website.( 2011/09/14)
follow sophos then the virus name: CXmal/FakeAV-A.
more info:
http://blog.bittorrent.com/2011/09/13/s ... -incident/
http://nakedsecurity.sophos.com/2011/09 ... d-for-p2p/
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Sep 23, 2011 8:26 am
by EP_X0FF
BTW regarding to previously posted by rough_spear sample. It's actually multiple dropper with 6 different malwares inside.
Alureon.DX (TDL4)
Cycbot.B (GBot)
Harnig.S (AdvLoad)
TotalProtect
Personal Shield downloader
Hosts trojan
Re: Malware Requests
PostPosted:Fri Sep 23, 2011 8:36 am
by bitx
hnpl2011 wrote:I'm looking for samples of the fakeAV (security shield) was hack bittorent website.( 2011/09/14)
follow sophos then the virus name: CXmal/FakeAV-A.
more info:
http://blog.bittorrent.com/2011/09/13/s ... -incident/
http://nakedsecurity.sophos.com/2011/09 ... d-for-p2p/
File attached :)
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Sep 23, 2011 2:35 pm
by CodeAddiction
Xylitol said:
"There is no serial form, for this fakeAV."
Thanks.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Tue Sep 27, 2011 10:19 pm
by Xylitol
Advanced PC Shield 2012
PostPosted:Thu Sep 29, 2011 9:29 pm
by Xylitol
Privacyn
PostPosted:Thu Sep 29, 2011 11:49 pm
by Striker
Privacyn

Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Sep 30, 2011 8:45 am
by EP_X0FF
More Security Sphere 2012 samples, VT 2/ 43 (4.7%)
66 files, multipart archive
pass: malware