Se afișează postările cu eticheta FakeRean. Afișați toate postările
Se afișează postările cu eticheta FakeRean. Afișați toate postările

marți, 3 septembrie 2019

Advanced Security Tool 2010 FakeRean

Advanced Security Tool 2010 is a rogue antivirus software once running it start implanting itself using a mof file and batch file to enter the rogue by itself in real legitimate windows security center
Interface GUI Is like this :
This is one not actually reskined by safety Antispyware and WinPC Defender however fakerean is tripled itself rogue family or other multiple times
How he implant itself to legitimate security center
He first open itself a batch file with command wscui.cpl and mofcomp it use the security center resources and command to make the rogue product visible to real security center

Look in trial version
So looking at other payloads and he also drop viruses junk files to be classifited as virus malware backdoor trojan and other it make invalid exe dll reg acebot and other it have random files name.
 If we ignore or click close or later or something to continue unprotected look like that

So i decided to activate the rogue :
 The version of activation is differently too far this rogue does not require email so pretty fragile for a little cracking for his code.
 Once we ignore bypass activation or a payload alert we got this
 And if we wanna to make change to turn off and on we got also this

I forgot once restart pc we get the payload un used by the rogue. replace explorer.
And support ?
 Here is all ingredients from this fakerean they are so located in %appdata%
asectool.exe md5 : a2f34f8c19beaff52730fd438570e133
He drop most of the files
So the payload like firewall alert is sinister :
It use the username of the PC And the ComputerName
Also update black version
This version is not blocking little bit from executables


I am also asked are you sure?


Activation Code after i debug little bit here is code i found :
3547-74831239063-9802

 After activation it show the code that is valid and store into registry Called Advanced Security
The dialog is a braviax looking window.
After i activated i need to cleanup and restart program.WHAT??
Threat removed.

Once activated i can also update but he refresh the inject of security center files because is turned on high protection
 Full version still no threats :
 Let's do an update



 And the legitimate security center was disabled or notify that rogue up to date and scanning virus on
You have to erase him with MBAM

I also tested on windows 10 and higher os but most fully error and compatibility mode to XP
Video Review i release him video review in 2017 and i cracked in 2019:

sâmbătă, 27 aprilie 2019

Safety Anti-Spyware Rogue FakeRean

Safety-Antispyware is a rogue antispyware program issuing that he is from fakerean and he is first than Winpcdefender.
The file is hidding itself and copy install itself to program files.
When loaded he show a red interface infected malware
Interface may look like that :
His threats detected are win32.i.1.2.3 and most :
His payloads only one :
His fakerean behavior is showing every 10 minutes or high also seen this warning on Winpcdefender xp deluxe protector WinPC Antivirus and more
If we try to turn off and on :

Is told us lore to get full version :
If we click no or if we ignore activation i am unprotected by spyware :
 And showing that pop up on taskbar the icon also seen by other rogues IE-Defender Files-Secure etc.
All protection level low grammar errors :(
Image of red Low :

The Activation :
 Not Fair the activation regcode and registry hack i should use a debug or pe explorer to get a key.
After i put a correctly code : is 12345
Is making me to put a valid email fake or rean including the "@" aol symbol.
 Finally activated with a fake email and registration key : rafael@safetyantispywareshop.com
Key 12345
Once Restarted on fullversion the registry is random but the GUI interface is changed into green :
Anything Enabled :
 Turned on Everything and subscription updated Fake


 The privacy control.Also once the threats are detected they are removed easy and we unlocked Exit safetyantispyware
Finally i uninstalled this fakeantivirus from control panel and uninstalled from recyclebin using a batch file. But the main program is attrib to be hidden

I see that folder on recycle bin and i can remove this program and registry when is needed.
He still have a safetyantispyware 3
Filename detalis :
SafetyAntiSpyware3.exe
MD5 : 848aea51e9d26089982c9b820c2ea4ba
AV RESULTS :
MS : Rogue:Win32/FakeRean
Kapersky Trojan.Win32.Inject.alyb
Eset : Adware.Safetyantispyware
I explorer that rogue since 2018 :
Thanks Virusshare for confirmation :
Video Demonstration and Review : 


  Activation :
Imagine how easy code simple but naive users spent money on this software rogue :D

joi, 31 ianuarie 2019

Desktop Security 2010 - Primary Version FakeRean - Fake Antivirus

Desktop Security 2010 is a primary version that looks like Desktop Defender 2010.
And his installer interface have a green and closed and bright.

After Install he drops junk files and while scanning a voice "NEW VIRUS FOUND" Is hearing on any audio device
His Gui and perfomance issue risk high threat.
Once installed he disable legitimate security center and replace with his false alerts that pretend to be security center by saying Your computer is might be at risk :
The alerts we are meeting while other alerts saying virus alert.
Once we try to ignore it rediects to some options and activation process.
The alerts will look like this.
Will display Spyware Alert , Possible loss of data and mass mail worm

 Once we press a button there is no way to escape :


After ignore will do a unwanted payload.
More worst problems with false alerts is securitycenter.exe he create junk sounds and loud effects and flashing the screen colors and pretend that computer perfomance or something is infected by malware.It Also do a black screen for a while.
Other Alert are behave like security center unknown alert

Nothing will escape the alerts.Also this trojan was helped and sync with other exe files.
If you try to open a program like browser wmplayer mspaint bdcam and more in primary version will show a error like this:
 On pressing on OK Button or anything the scan has been started with new virus found
This Sound VIRUS FOUND it display another alerts :



This alert create a lot of junk and bad files in temp folder.
Less KB and once we try to delete or open them more errors.

And another one that show windows register license info

And After fake alerts a fake blue screen will be show.
After Reboot a hijacked winlogon shell will be right now :
The fake blue screen error will be prepared after 30 minutes of unused pc.
As part the rogue antivirus hijacks and opens a fake task manager

He use a taskmgr.dll to hijack and inject.Virus free processes are free kill and any attempt to kill a process INFECTED will rediect to activation.
And blank and other payload (Blank screen flashing and loud sound the loud sound was also hear by mixer)
The process.
The program files will look like this :
The setup file called SoftwareInstall[1].exe
MD5
14c54dc822a59ccbd436ef226ddb648b
SHA-1
87d620edf59390371066daebb86e0cc081b38c2d
SHA-256
493a1fce7927471d9c745d6bddd8aa9ce7944d3b06de64404664e243c44d3b94
 The av results are
Avira : TR/FakeAV.CD.1
F-prot W32/MalwareS.ITF
ESET ADWARE.DESKTOPDEFENDER2010.AC
Microsoft : Rogue:Win32/FakeRean
Kapersky :  Trojan.Win32.FakeAV.cd
And More.
And the activation process.Key is : LIC-1800-FE88-8788-BBED-B26C-899B-14A6-4503-4618-EB85-B7A8-371D-1097-FEBC-B41D-C2B1-7A5F
Same as antivirus solution 2010.He store this key in his registry.
 His Activation Message is changed or is primary Well

 No more annoying things so update is died.
The uninstall Process :
 We need a Key to remove the software and reset so this will work after activation.My Machine id is 92o5n9autvod
Grammar Error very idiotic.
After i debug the uninstall key for my differently machine ID 
 YAY! Here is my private uninstall key : b139228c3241c03a0b0979fde5dd6c2d
Removing This will work only on full version for security reasons.Reseting shell and remove files.
In conclunsion he have same payload as antivirus solution 2010 must go Here.
Bonus some help offline file similar to his official site and payment page
His Page Will look like this :
Video Review :
This was tested on a xp and attempt rkill fail so i see a lot of stuff like that.
I Will post more about discovered malwarerogue thing. :)
Post about upgraded soon.