Page 3 of 46
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Mon Jan 23, 2012 10:50 pm
by Xylitol
Unpacked version in attach.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Tue Jan 24, 2012 8:39 am
by rkhunter
FakeSysdef FUD
MD5: 6021fc3aa1295316b9a0031a3a4b4edc
0/43
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Tue Jan 24, 2012 6:32 pm
by Xylitol
Malware Protection Center
MP9c5_8040.exe:
7/41
Setup.exe:
10/43

Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Wed Jan 25, 2012 8:27 am
by rkhunter
FakeRean - XP Home Security 2012
Above code works fine.
MD5: d8ef22258cd52c78d722a0be5589d93c
13/41
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Wed Jan 25, 2012 8:56 am
by rkhunter
24 FakeSysdef samples
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Jan 26, 2012 9:05 am
by rkhunter
Security Shield Pro 2011 - Rogue:Win32/Winwebsec.
Realy looks like normal anti-malware tool, because found really infected files.
MD5: bc83e4ab803b8e18114dee369504fabf
17/43
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Thu Jan 26, 2012 9:13 am
by rkhunter
Security Shield - Winwebsec
MD5: e23b58ba4d6ed87e7f3fb6fbdb0724d0
11/42
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Fri Jan 27, 2012 10:02 pm
by Neurofunk
Found along with a binary for rootkit.boot.SST.b and FakeSysDef.
FakeAV.Win32.FakeRecovery
MD5: fd635b2cb292142d237c2e0c4a8b2ccf
Detection ratio:
9 / 42
Analysis date: 2012-01-27 21:12:21 UTC
https://www.virustotal.com/file/6da519e ... 327698741/
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sat Jan 28, 2012 4:07 am
by rkhunter
Neurofunk wrote:
FakeAV.Win32.FakeRecovery
MD5: fd635b2cb292142d237c2e0c4a8b2ccf
This is FakeSysdef.
Re: Rogue antimalware (FakeAV, FakeAlert)
PostPosted:Sat Jan 28, 2012 6:16 pm
by markusg
FakeSysdef (systemcheck):
mCl7w2YFKX8LGN.exe
SHA256:
8449f1762b8c23c8f72fe8944fff7d034dfe10fcb466d4596be0388ce54b1b68
https://www.virustotal.com/file/8449f17 ... 327774264/