Page 3 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Jan 23, 2012 10:50 pm
by Xylitol
Unpacked version in attach.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Jan 24, 2012 8:39 am
by rkhunter
FakeSysdef FUD

MD5: 6021fc3aa1295316b9a0031a3a4b4edc
0/43

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Jan 24, 2012 6:32 pm
by Xylitol
Malware Protection Center

MP9c5_8040.exe: 7/41
Setup.exe: 10/43

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Jan 25, 2012 8:27 am
by rkhunter
FakeRean - XP Home Security 2012
Above code works fine.

MD5: d8ef22258cd52c78d722a0be5589d93c
13/41

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Jan 25, 2012 8:56 am
by rkhunter
24 FakeSysdef samples

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Jan 26, 2012 9:05 am
by rkhunter
Security Shield Pro 2011 - Rogue:Win32/Winwebsec.
Realy looks like normal anti-malware tool, because found really infected files.

Image

MD5: bc83e4ab803b8e18114dee369504fabf
17/43

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Jan 26, 2012 9:13 am
by rkhunter
Security Shield - Winwebsec

Image

MD5: e23b58ba4d6ed87e7f3fb6fbdb0724d0
11/42

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Jan 27, 2012 10:02 pm
by Neurofunk
Found along with a binary for rootkit.boot.SST.b and FakeSysDef.

FakeAV.Win32.FakeRecovery
MD5: fd635b2cb292142d237c2e0c4a8b2ccf
Detection ratio: 9 / 42
Analysis date: 2012-01-27 21:12:21 UTC
https://www.virustotal.com/file/6da519e ... 327698741/

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Jan 28, 2012 4:07 am
by rkhunter
Neurofunk wrote: FakeAV.Win32.FakeRecovery
MD5: fd635b2cb292142d237c2e0c4a8b2ccf
This is FakeSysdef.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sat Jan 28, 2012 6:16 pm
by markusg
FakeSysdef (systemcheck):
mCl7w2YFKX8LGN.exe

SHA256:
8449f1762b8c23c8f72fe8944fff7d034dfe10fcb466d4596be0388ce54b1b68 
https://www.virustotal.com/file/8449f17 ... 327774264/