What up with biz?
http://blogs.technet.com/b/mmpc/archive ... light.aspx
http://blogs.technet.com/b/mmpc/archive ... light.aspx
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
EP_X0FF wrote:What up with biz?FakeAV's want to be lockers, kinda cute.
http://blogs.technet.com/b/mmpc/archive ... light.aspx
ISergey256 wrote:Rogue:Win32/DefruThanks!
https://www.virustotal.com/uk/file/24ec ... /analysis/
iShare wrote:Pretty boring, a very n00b rogue proxy, redirecting all visited websites to fake av download pageAh, yes! This is really a lame FakeAV. Just infecting the host-file.. I thought this was something good.
bandicoot_ wrote:Hi, this is my first post on the forums.Welcome, i suggest you to read the forum rules: http://www.kernelmode.info/forum/viewtopic.php?f=8&t=16
bandicoot_ wrote:While looking in the payment page, i found that the website for the rogue above is [url]hxxp://www.softcleaning.net[/url]What i said just before your post:
Xylitol wrote:• dns: 1 ›› ip: 146.0.79.164 - adress: SOFTCLEANING.NET
bandicoot_ wrote:(Warning: WILL infect!!!)I don't see any hostile code on this site.