A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #10415  by Cody Johnston
 Fri Dec 16, 2011 7:18 pm
XP AntiSpyware 2012

http://imgur.com/hYupd

http://www.virustotal.com/file-scan/rep ... 1324000564

Very low detection rate: 2 /42 (4.8%)

Also, there is no place to enter serial on this one.

EDIT: Picture link corrected
Attachments
Password: infected
(1.7 MiB) Downloaded 69 times
 #10420  by BachMinuetInG
 Sat Dec 17, 2011 4:51 am
TeamRocketOps wrote:XP AntiSpyware 2012

http://imgur.com/hYupd

http://www.virustotal.com/file-scan/rep ... 1324000564

Very low detection rate: 2 /42 (4.8%)

Also, there is no place to enter serial on this one.

EDIT: Picture link corrected
That is a 'registered' version of an 'unregistered' software. Weird though...
 #10551  by Grinler
 Fri Dec 23, 2011 1:24 am
Looks like someone is trying to capitalize on MBAM's name.

Not familiar with what they are peddling, but looks like standard crapware.
 #10556  by Xylitol
 Fri Dec 23, 2011 3:24 pm
True Big Cash Affiliate (Security Defender)
http://xylibox.blogspot.com/2011/12/tra ... -cash.html
Code: Select all
http://94.61.247.181/l.exe?rwmid=1&wmid=284
Image

Image

Image

in attach, one sample.
Attachments
pw: infected
(72.63 KiB) Downloaded 62 times
 #10563  by BachMinuetInG
 Sat Dec 24, 2011 2:30 am
Security Defender
Security Defender files... This seem to be very rapidly spreading. :o :o
Large collection. :)
No password. Plus:
Posting up photos of the different browsers 'fake scanner' interface here:
http://xwxprod.tk/
Attachments
pass: malware
(1.12 MiB) Downloaded 70 times
 #10580  by Xylitol
 Sun Dec 25, 2011 10:51 am
Home Security Solutions
xmas fakeav

Image

16/43 >> 37.2%
http://www.virustotal.com/file-scan/rep ... 1324809754

That won't extract payload for me, if someone can provid (HSf48_7.exe or something like this)
edit: alright it's in attach
http://www.virustotal.com/file-scan/rep ... 1324818695
Code: Select all
c:\mvelbaneim11\ncipnaiareu.kla
$report=%s&appType=%1d&mid=%s&ls=%s&uid=%s&wv=%s&pid=%s&isStart=%d$
D:\Work\AdwareProjects\DeskTopWork\Cleaners\VirusDoctor
SOFTWARE\BitDefender\
SOFTWARE\KasperskyLab\
SOFTWARE\4\
SOFTWARE\3\
SOFTWARE\Zone Labs\ZoneAlarm\
SOFTWARE\Eset\Nod\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WebrootDesktopFirewall.exe\
SOFTWARE\Symantec\Norton AntiVirus\
SOFTWARE\Sophos\SAVService\Application\
SOFTWARE\rising\Rav\
SOFTWARE\KasperskyLab\InstalledProducts\Kaspersky Anti-Virus Personal\
SOFTWARE\Data Fellows\F-Secure\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E58B329B-FB28-4874-90DE-0D7CB2709267}\
SOFTWARE\BitDefender\BitDefender Antivirus 2008\
SOFTWARE\AVG\
SOFTWARE\ComodoGroup\CDI\
SOFTWARE\Agnitum\Security Suite\
Virus1Doctor1Installer1Mutex1
ls;bid;uid;"http://trdatasft.com;trdatasft.com
SetupRelease.cab
SetupReleaseXP.cab
http://76.73.19.182/
TMainWindowHSS!HOME_SECURITY_SOLUTIONS_UNINSTALL
HomeSS.exe
HOME_SECURITY_SOLUTIONS_APP0http://www5.thebest-av-foryou.com/uninstall.php?
SetupReleaseXP.cab
Setup.exe
Home Security Solutions!HOME_SECURITY_SOLUTIONS_APP_CLOSE/http://save-secure.com;http://securityearth.net
reports/get_install_file.php
/index.php
/index.php
WDC WD3200AAJS-00YZCA0
WD-WCAYU4523231
• dns: 1 ›› ip: 76.73.19.180 - adresse: WWW5.THEBEST-AV-FORYOU.COM
Image

• dns: 1 ›› ip: 76.73.19.178 - adresse: SECURE1.SMARTWASUITE.COM
Image
Attachments
pw: infected
(2.51 MiB) Downloaded 102 times
pw: infected
(3.09 MiB) Downloaded 92 times
pw: infected
(147.49 KiB) Downloaded 64 times
 #10620  by BachMinuetInG
 Tue Dec 27, 2011 11:40 am
FakeAV Please wait! This is important we check your device, VClean_Setup.exe
hxxp://onlinescanner.ru/scanner/?param=158#9
Attachment will be posted later on.
Attachments
Password: xwxprod
(221.03 KiB) Downloaded 56 times
  • 1
  • 30
  • 31
  • 32
  • 33
  • 34